0

Final Class Yiisoft\Yii\AuthClient\Client\OpenIdConnect

InheritanceYiisoft\Yii\AuthClient\Client\OpenIdConnect » Yiisoft\Yii\AuthClient\OAuth2 » Yiisoft\Yii\AuthClient\OAuth » Yiisoft\Yii\AuthClient\AuthClient
ImplementsYiisoft\Yii\AuthClient\AuthClientInterface, Yiisoft\Yii\AuthClient\OAuth2Interface, Yiisoft\Yii\AuthClient\OAuthInterface

OpenIdConnect serves as a client for the OpenIdConnect flow.

See also Yiisoft\Yii\AuthClient\OAuth2.

Protected Properties

Hide inherited properties

Property Type Description Defined By
$accessToken array|Yiisoft\Yii\AuthClient\OAuthToken|null Access token instance or its array configuration. Yiisoft\Yii\AuthClient\OAuth
$authParams array Additional auth GET params, merged into every {@see \Yiisoft\Yii\AuthClient\buildAuthUrl()} call. Yiisoft\Yii\AuthClient\OAuth2
$authUrl string Authorize URL. Yiisoft\Yii\AuthClient\OAuth
$autoRefreshAccessToken boolean Whether to automatically perform 'refresh access token' request on expired access token. Yiisoft\Yii\AuthClient\OAuth
$clientId string OAuth client ID. Yiisoft\Yii\AuthClient\OAuth2
$clientSecret string OAuth client secret. Yiisoft\Yii\AuthClient\OAuth2
$endpoint string API base URL. Yiisoft\Yii\AuthClient\OAuth
$environment string Environment identifier (e.g. 'dev' or 'prod'), for providers whose endpoint URLs differ by environment. Yiisoft\Yii\AuthClient\OAuth2
$factory \Yiisoft\Factory\Factory Yiisoft\Yii\AuthClient\OAuth2
$httpClient \Psr\Http\Client\ClientInterface Yiisoft\Yii\AuthClient\AuthClient
$name string Custom name, set from the config array key. Yiisoft\Yii\AuthClient\AuthClient
$normalizeUserAttributeMap array Map used to normalize user attributes fetched from external auth service in format: normalizedAttributeName => sourceSpecification 'sourceSpecification' can be: - string, raw attribute name - array, pass to raw attribute value - callable, PHP callback, which should accept array of raw attributes and return normalized value. Yiisoft\Yii\AuthClient\AuthClient
$requestFactory \Psr\Http\Message\RequestFactoryInterface Yiisoft\Yii\AuthClient\AuthClient
$returnUrl string Yiisoft\Yii\AuthClient\OAuth2
$scope ?string Yiisoft\Yii\AuthClient\Client\OpenIdConnect
$session \Yiisoft\Session\SessionInterface Yiisoft\Yii\AuthClient\OAuth2
$title string Custom title, overrides the class default if set. Yiisoft\Yii\AuthClient\AuthClient
$tokenUrl string Token request URL endpoint. Yiisoft\Yii\AuthClient\OAuth2
$validateAuthState boolean Whether to use and validate auth 'state' parameter in authentication flow. Yiisoft\Yii\AuthClient\OAuth2
$viewOptions array View options in format: optionName => optionValue Yiisoft\Yii\AuthClient\AuthClient

Public Methods

Hide inherited methods

Method Description Defined By
__construct() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
api() Performs request to the OAuth API returning response data. Yiisoft\Yii\AuthClient\OAuth
applyAccessTokenToRequest() Yiisoft\Yii\AuthClient\OAuth2
beforeApiRequestSend() Yiisoft\Yii\AuthClient\OAuth
buildAuthUrl() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
createApiRequest() Creates an HTTP request for the API call. Yiisoft\Yii\AuthClient\OAuth
createRequest() Yiisoft\Yii\AuthClient\AuthClient
fetchAccessToken() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
fetchAccessTokenWithCodeVerifier() Note: This function will be adapted later to accomodate the 'confidential client'. Yiisoft\Yii\AuthClient\OAuth2
getAccessToken() Yiisoft\Yii\AuthClient\OAuth
getAuthParams() Yiisoft\Yii\AuthClient\OAuth2
getClientId() Yiisoft\Yii\AuthClient\OAuth2
getClientSecret() Yiisoft\Yii\AuthClient\OAuth2
getConfigParam() Returns particular configuration parameter value. Yiisoft\Yii\AuthClient\Client\OpenIdConnect
getConfigParams() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
getCurrentUserJsonArray() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
getLogo() Yiisoft\Yii\AuthClient\OAuth2
getName() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
getNormalizeUserAttributeMap() Yiisoft\Yii\AuthClient\AuthClient
getOauth2ReturnUrl() Yiisoft\Yii\AuthClient\OAuth2
getRequestFactory() Yiisoft\Yii\AuthClient\AuthClient
getReturnUrl() Yiisoft\Yii\AuthClient\OAuth
getScope() Yiisoft\Yii\AuthClient\OAuth
getSessionAuthState() Compare a callback query parameter 'state' with the saved Auth Client's 'authState' parameter in order to prevent CSRF attacks Yiisoft\Yii\AuthClient\OAuth2
getTitle() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
getTokenUrl() Yiisoft\Yii\AuthClient\OAuth2
getUserAttributes() Returns the authenticated user's attributes, as fetched by {@see initUserAttributes()} and normalized according to {@see normalizeUserAttributeMap}. Yiisoft\Yii\AuthClient\AuthClient
getValidateAuthNonce() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
getViewOptions() Yiisoft\Yii\AuthClient\AuthClient
getYiisoftFactory() Yiisoft\Yii\AuthClient\OAuth
refreshAccessToken() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
setAccessToken() Sets access token to be used. Yiisoft\Yii\AuthClient\OAuth
setAuthParams() Yiisoft\Yii\AuthClient\OAuth2
setAuthUrl() Yiisoft\Yii\AuthClient\OAuth
setClientId() Yiisoft\Yii\AuthClient\OAuth2
setClientSecret() Yiisoft\Yii\AuthClient\OAuth2
setEnvironment() Yiisoft\Yii\AuthClient\OAuth2
setIssuerUrl() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
setLogo() Yiisoft\Yii\AuthClient\OAuth2
setName() Yiisoft\Yii\AuthClient\AuthClient
setOauth2ReturnUrl() Yiisoft\Yii\AuthClient\OAuth2
setRequestFactory() Yiisoft\Yii\AuthClient\AuthClient
setReturnUrl() Yiisoft\Yii\AuthClient\OAuth
setScope() Yiisoft\Yii\AuthClient\OAuth
setTitle() Yiisoft\Yii\AuthClient\AuthClient
setTokenUrl() Yiisoft\Yii\AuthClient\OAuth2
setValidateAuthNonce() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
setYiisoftFactory() Yiisoft\Yii\AuthClient\OAuth
withValidateAuthState() Yiisoft\Yii\AuthClient\OAuth2
withValidateJws() Enables JWS validation/decryption of the auth token (the default). See {@see validateJws} for details. Yiisoft\Yii\AuthClient\Client\OpenIdConnect
withoutValidateAuthState() Yiisoft\Yii\AuthClient\OAuth2
withoutValidateJws() Disables JWS validation/decryption of the auth token. See {@see validateJws} for the trade-offs of doing so. Yiisoft\Yii\AuthClient\Client\OpenIdConnect

Protected Methods

Hide inherited methods

Method Description Defined By
applyClientCredentialsToRequest() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
createToken() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
createTokenRequest() Builds a POST request to {@see tokenUrl} with $params as an application/x-www-form-urlencoded body. RFC 6749 §4.1.3 requires token-endpoint parameters in the request body, not the URI query string - a strict provider like Google rejects a query-string-only request outright (with no usable access_token in its error response), while a lenient one like GitHub's legacy endpoint happens to tolerate it. {@see applyClientCredentialsToRequest()} is expected to append further params to this same body afterward, not build a request of its own. Yiisoft\Yii\AuthClient\OAuth2
defaultNormalizeUserAttributeMap() Returns the default {@see normalizeUserAttributeMap} value. Yiisoft\Yii\AuthClient\AuthClient
defaultReturnUrl() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
defaultViewOptions() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
fetchCurrentUserJsonArray() Fetches current user data as JSON array from the given endpoint, authenticating the request with the access token as an Authorization header. Yiisoft\Yii\AuthClient\OAuth2
generateAuthNonce() Generates the auth nonce value. Yiisoft\Yii\AuthClient\Client\OpenIdConnect
generateAuthState() Generates the auth state value. Yiisoft\Yii\AuthClient\OAuth2
generateAuthStateBaseString() Builds the seed string used by {@see generateAuthState()}. Extracted into its own method so the seed's composition can be tested directly, since the final hashed/uniqid()-mixed auth state value is opaque and can't reveal how its input was assembled. Yiisoft\Yii\AuthClient\OAuth2
getDefaultScope() Yiisoft\Yii\AuthClient\OAuth
getJwkSet() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
getJwsLoader() Returns the JWSLoader that validates the JWS token. Yiisoft\Yii\AuthClient\Client\OpenIdConnect
getState() Returns persistent state value. Yiisoft\Yii\AuthClient\AuthClient
getStateKeyPrefix() Returns session key prefix, which is used to store internal states. Yiisoft\Yii\AuthClient\AuthClient
initUserAttributes() Yiisoft\Yii\AuthClient\Client\OpenIdConnect
loadJws() Decrypts/validates JWS, returning related data. Yiisoft\Yii\AuthClient\Client\OpenIdConnect
removeState() Removes persistent state value. Yiisoft\Yii\AuthClient\AuthClient
restoreAccessToken() Restores access token. Yiisoft\Yii\AuthClient\OAuth
saveAccessToken() Saves token as persistent state. Yiisoft\Yii\AuthClient\OAuth
sendRequest() Yiisoft\Yii\AuthClient\AuthClient
setState() Sets persistent state. Yiisoft\Yii\AuthClient\AuthClient
validateClaims() Validates the claims data received from the OpenID provider. Yiisoft\Yii\AuthClient\Client\OpenIdConnect

Property Details

Hide inherited properties

$scope protected property
protected ?string $scope 'openid'

Method Details

Hide inherited methods

__construct() public method

public mixed __construct ( \Psr\Http\Client\ClientInterface $httpClient, \Psr\Http\Message\RequestFactoryInterface $requestFactory, Yiisoft\Yii\AuthClient\StateStorage\StateStorageInterface $stateStorage, \Yiisoft\Factory\Factory $factory, \Yiisoft\Session\SessionInterface $session, \Psr\SimpleCache\CacheInterface $cache )
$httpClient \Psr\Http\Client\ClientInterface
$requestFactory \Psr\Http\Message\RequestFactoryInterface
$stateStorage Yiisoft\Yii\AuthClient\StateStorage\StateStorageInterface
$factory \Yiisoft\Factory\Factory
$session \Yiisoft\Session\SessionInterface
$cache \Psr\SimpleCache\CacheInterface

                public function __construct(
    ClientInterface $httpClient,
    RequestFactoryInterface $requestFactory,
    StateStorageInterface $stateStorage,
    Factory $factory,
    SessionInterface $session,
    private readonly CacheInterface $cache,
) {
    parent::__construct($httpClient, $requestFactory, $stateStorage, $factory, $session);
}

            
api() public method

Defined in: Yiisoft\Yii\AuthClient\OAuth::api()

Performs request to the OAuth API returning response data.

You may use {@see \Yiisoft\Yii\AuthClient\createApiRequest()} method instead, gaining more control over request execution.

See also createApiRequest().

public array api ( string $apiSubUrl, string $method 'GET', array|string $data = [], array $headers = [] )
$apiSubUrl string

API sub URL, which will be append to {@see \Yiisoft\Yii\AuthClient\apiBaseUrl}, or absolute API URL.

$method string

Request method.

$data array|string

Request data or content.

$headers array

Additional request headers.

return array

API response data.

throws Exception

                public function api($apiSubUrl, $method = 'GET', $data = [], $headers = []): array
{
    $request = $this->createApiRequest($method, $apiSubUrl);
    $request = RequestUtil::addHeaders($request, $headers);
    if (!empty($data)) {
        if (is_array($data)) {
            $request = RequestUtil::addParams($request, $data);
        } else {
            $request->getBody()->write($data);
        }
    }
    $request = $this->beforeApiRequestSend($request);
    $response = $this->sendRequest($request);
    if ($response->getStatusCode() !== 200) {
        throw new InvalidResponseException(
            $response,
            'Request failed with code: ' . $response->getStatusCode() . ', message: ' . $response->getBody(),
        );
    }
    return (array) Json::decode($response->getBody()->getContents());
}

            
applyAccessTokenToRequest() public method
public \Psr\Http\Message\RequestInterface applyAccessTokenToRequest ( \Psr\Http\Message\RequestInterface $request, Yiisoft\Yii\AuthClient\OAuthToken $accessToken )
$request \Psr\Http\Message\RequestInterface
$accessToken Yiisoft\Yii\AuthClient\OAuthToken

                public function applyAccessTokenToRequest(RequestInterface $request, OAuthToken $accessToken): RequestInterface
{
    return RequestUtil::addParams(
        $request,
        [
            'access_token' => $accessToken->getToken(),
        ],
    );
}

            
applyClientCredentialsToRequest() protected method

protected \Psr\Http\Message\RequestInterface applyClientCredentialsToRequest ( \Psr\Http\Message\RequestInterface $request )
$request \Psr\Http\Message\RequestInterface

                protected function applyClientCredentialsToRequest(RequestInterface $request): RequestInterface
{
    $supportedAuthMethods = (array) $this->getConfigParam('token_endpoint_auth_methods_supported');
    if (in_array('client_secret_basic', $supportedAuthMethods, true)) {
        return $this->applyClientSecretBasic($request);
    }
    if (in_array('client_secret_post', $supportedAuthMethods, true)) {
        return $this->applyClientSecretPost($request);
    }
    if (in_array('client_secret_jwt', $supportedAuthMethods, true)) {
        return $this->applyClientSecretJwt($request);
    }
    throw new InvalidConfigException('Unable to authenticate request: No auth method supported');
}

            
beforeApiRequestSend() public method
public \Psr\Http\Message\RequestInterface beforeApiRequestSend ( \Psr\Http\Message\RequestInterface $request )
$request \Psr\Http\Message\RequestInterface

                public function beforeApiRequestSend(RequestInterface $request): RequestInterface
{
    $accessToken = $this->getAccessToken();
    if (!is_object($accessToken) || !$accessToken->getIsValid()) {
        throw new Exception('Invalid access token.');
    }
    return $this->applyAccessTokenToRequest($request, $accessToken);
}

            
buildAuthUrl() public method

public string buildAuthUrl ( \Psr\Http\Message\ServerRequestInterface $incomingRequest, array $params = [] )
$incomingRequest \Psr\Http\Message\ServerRequestInterface
$params array

                public function buildAuthUrl(ServerRequestInterface $incomingRequest, array $params = []): string
{
    if (empty($this->authUrl)) {
        $this->authUrl = (string) $this->getConfigParam('authorization_endpoint');
    }
    return parent::buildAuthUrl($incomingRequest, $params);
}

            
createApiRequest() public method

Defined in: Yiisoft\Yii\AuthClient\OAuth::createApiRequest()

Creates an HTTP request for the API call.

The created request will be automatically processed adding access token parameters and signature before sending. You may use {@see \Yiisoft\Yii\AuthClient\createRequest()} to gain full control over request composition and execution.

See also createRequest().

public \Psr\Http\Message\RequestInterface createApiRequest ( string $method, string $uri )
$method string
$uri string
return \Psr\Http\Message\RequestInterface

HTTP request instance.

                public function createApiRequest(string $method, string $uri): RequestInterface
{
    return $this->createRequest($method, $this->endpoint . $uri);
}

            
createRequest() public method
public \Psr\Http\Message\RequestInterface createRequest ( string $method, string $uri )
$method string
$uri string

                public function createRequest(string $method, string $uri): RequestInterface
{
    return $this->requestFactory->createRequest($method, $uri);
}

            
createToken() protected method

protected Yiisoft\Yii\AuthClient\OAuthToken createToken ( array $tokenConfig = [] )
$tokenConfig array

                protected function createToken(array $tokenConfig = []): OAuthToken
{
    $params = (array) $tokenConfig['params'];
    $idToken = (string) ($params['id_token'] ?? '');
    if ($this->validateJws) {
        $jwsData = $this->loadJws($idToken);
        $this->validateClaims($jwsData);
        $tokenConfig['params'] = array_merge($params, $jwsData);
        if ($this->getValidateAuthNonce()) {
            $nonce = isset($jwsData['nonce']) ? (string) $jwsData['nonce'] : '';
            $authNonce = (string) $this->getState('authNonce');
            if (!isset($jwsData['nonce']) || empty($authNonce) || strcmp($nonce, $authNonce) !== 0) {
                throw new ClientException('Invalid auth nonce', 400);
            }
            $this->removeState('authNonce');
        }
    }
    return parent::createToken($tokenConfig);
}

            
createTokenRequest() protected method

Defined in: Yiisoft\Yii\AuthClient\OAuth2::createTokenRequest()

Builds a POST request to {@see tokenUrl} with $params as an application/x-www-form-urlencoded body. RFC 6749 §4.1.3 requires token-endpoint parameters in the request body, not the URI query string - a strict provider like Google rejects a query-string-only request outright (with no usable access_token in its error response), while a lenient one like GitHub's legacy endpoint happens to tolerate it. {@see applyClientCredentialsToRequest()} is expected to append further params to this same body afterward, not build a request of its own.

protected \Psr\Http\Message\RequestInterface createTokenRequest ( array $params )
$params array

                protected function createTokenRequest(array $params): RequestInterface
{
    $request = $this->createRequest('POST', $this->tokenUrl)
        ->withHeader('Content-Type', 'application/x-www-form-urlencoded');
    $request->getBody()->write(http_build_query($params, arg_separator: '&', encoding_type: PHP_QUERY_RFC3986));
    return $request;
}

            
defaultNormalizeUserAttributeMap() protected method

Defined in: Yiisoft\Yii\AuthClient\AuthClient::defaultNormalizeUserAttributeMap()

Returns the default {@see normalizeUserAttributeMap} value.

Particular client may override this method in order to provide specific default map.

protected array defaultNormalizeUserAttributeMap ( )
return array

Normalize attribute map.

                protected function defaultNormalizeUserAttributeMap(): array
{
    return [];
}

            
defaultReturnUrl() protected method

protected string defaultReturnUrl ( \Psr\Http\Message\ServerRequestInterface $request )
$request \Psr\Http\Message\ServerRequestInterface

                protected function defaultReturnUrl(ServerRequestInterface $request): string
{
    $params = $request->getQueryParams();
    unset($params['code'], $params['state'], $params['nonce'], $params['authuser'], $params['session_state'], $params['prompt']);
    return (string) $request->getUri()->withQuery(
        http_build_query($params, arg_separator: '&', encoding_type: PHP_QUERY_RFC3986),
    );
}

            
defaultViewOptions() protected method

protected integer[] defaultViewOptions ( )

                protected function defaultViewOptions(): array
{
    return [
        'popupWidth' => 860,
        'popupHeight' => 480,
    ];
}

            
fetchAccessToken() public method

public Yiisoft\Yii\AuthClient\OAuthToken fetchAccessToken ( \Psr\Http\Message\ServerRequestInterface $incomingRequest, string $authCode, array $params = [] )
$incomingRequest \Psr\Http\Message\ServerRequestInterface
$authCode string
$params array

                public function fetchAccessToken(ServerRequestInterface $incomingRequest, string $authCode, array $params = []): OAuthToken
{
    $this->resolveTokenUrl();
    if (!isset($params['nonce']) && $this->getValidateAuthNonce()) {
        $nonce = $this->generateAuthNonce();
        $this->setState('authNonce', $nonce);
        $params['nonce'] = $nonce;
    }
    return parent::fetchAccessToken($incomingRequest, $authCode, $params);
}

            
fetchAccessTokenWithCodeVerifier() public method

Defined in: Yiisoft\Yii\AuthClient\OAuth2::fetchAccessTokenWithCodeVerifier()

Note: This function will be adapted later to accomodate the 'confidential client'.

See also https://docs.x.com/resources/fundamentals/authentication/oauth-2-0/authorization-code Used specifically for the X i.e. Twitter OAuth2.0 Authorization code with PKCE and public client i.e. client id included in request body; and NOT Confidential Client i.e. Client id not included in the request body.

public Yiisoft\Yii\AuthClient\OAuthToken fetchAccessTokenWithCodeVerifier ( \Psr\Http\Message\ServerRequestInterface $incomingRequest, string $authCode, array $params = [] )
$incomingRequest \Psr\Http\Message\ServerRequestInterface
$authCode string
$params array
throws InvalidArgumentException

                public function fetchAccessTokenWithCodeVerifier(
    ServerRequestInterface $incomingRequest,
    string $authCode,
    array $params = [],
): OAuthToken {
    if ($this->validateAuthState) {
        /**
         * @var string|null $authState 'authState' is only ever written by
         * {@see buildAuthUrl()} with the string returned from {@see generateAuthState()}.
         */
        $authState = $this->getState('authState');
        $queryParams = $incomingRequest->getQueryParams();
        $bodyParams = $incomingRequest->getParsedBody();
        /**
         * @psalm-suppress MixedAssignment
         */
        $incomingState = $queryParams['state'] ?? ($bodyParams['state'] ?? null);
        if (is_string($incomingState)) {
            if (strcmp($incomingState, (string) $authState) !== 0) {
                throw new InvalidArgumentException('Invalid auth state parameter.');
            }
        }
        if ($incomingState === null) {
            throw new InvalidArgumentException('Invalid auth state parameter.');
        }
        if (empty($authState)) {
            throw new InvalidArgumentException('Invalid auth state parameter.');
        }
        $this->removeState('authState');
    }
    $requestBody = [
        'code' => $authCode,
        'grant_type' => 'authorization_code',
        'client_id' => $this->clientId,
        'client_secret' => $this->clientSecret,
        'redirect_uri' => $params['redirect_uri'] ?? '',
        'code_verifier' => $params['code_verifier'] ?? '',
    ];
    $request = $this->requestFactory
        ->createRequest('POST', $this->tokenUrl)
        ->withHeader(Header::CONTENT_TYPE, 'application/x-www-form-urlencoded');
    $request->getBody()->write(
        http_build_query($requestBody, arg_separator: '&', encoding_type: PHP_QUERY_RFC3986),
    );
    try {
        $response = $this->httpClient->sendRequest($request);
        $body = $response->getBody()->getContents();
        $output = (array) Json::decode($body);
    } catch (Throwable) {
        $output = [];
    }
    $token = $this->createToken(['params' => $output]);
    $this->setAccessToken($token);
    return $token;
}

            
fetchCurrentUserJsonArray() protected method

Defined in: Yiisoft\Yii\AuthClient\OAuth2::fetchCurrentUserJsonArray()

Fetches current user data as JSON array from the given endpoint, authenticating the request with the access token as an Authorization header.

protected array fetchCurrentUserJsonArray ( Yiisoft\Yii\AuthClient\OAuthToken $token, string $url, array $headers = [], string $authScheme 'Bearer' )
$token Yiisoft\Yii\AuthClient\OAuthToken

Access token, whose access_token param is used for authentication.

$url string

Endpoint URL to fetch user data from.

$headers array

Additional request headers, merged over the default Authorization header.

$authScheme string

Authorization header scheme, e.g. Bearer or OAuth.

return array

Decoded user data, or an empty array if there is no access token or the request fails.

                protected function fetchCurrentUserJsonArray(
    OAuthToken $token,
    string $url,
    array $headers = [],
    string $authScheme = 'Bearer',
): array {
    $tokenString = (string) $token->getParam('access_token');
    if ($tokenString === '') {
        return [];
    }
    $request = RequestUtil::addHeaders(
        $this->createRequest('GET', $url),
        array_merge(['Authorization' => $authScheme . ' ' . $tokenString], $headers),
    );
    if ($request->getHeaderLine('User-Agent') === '') {
        $request = $request->withHeader('User-Agent', 'yiisoft/yii-auth-client');
    }
    try {
        $body = $this->sendRequest($request)->getBody()->getContents();
    } catch (Throwable) {
        return [];
    }
    return $body === '' ? [] : (array) Json::decode($body);
}

            
generateAuthNonce() protected method

Generates the auth nonce value.

protected string generateAuthNonce ( )
return string

Auth nonce value.

throws Exception

                protected function generateAuthNonce(): string
{
    return Random::string();
}

            
generateAuthState() protected method

Defined in: Yiisoft\Yii\AuthClient\OAuth2::generateAuthState()

Generates the auth state value.

protected string generateAuthState ( )
return string

Auth state value.

                protected function generateAuthState(): string
{
    return hash('sha256', uniqid($this->generateAuthStateBaseString(), true));
}

            
generateAuthStateBaseString() protected method

Defined in: Yiisoft\Yii\AuthClient\OAuth2::generateAuthStateBaseString()

Builds the seed string used by {@see generateAuthState()}. Extracted into its own method so the seed's composition can be tested directly, since the final hashed/uniqid()-mixed auth state value is opaque and can't reveal how its input was assembled.

protected string generateAuthStateBaseString ( )
return string

Auth state seed.

                protected function generateAuthStateBaseString(): string
{
    $baseString = static::class . '-' . time();
    $sessionId = $this->session->getId();
    if (null !== $sessionId) {
        if ($this->session->isActive()) {
            $baseString .= '-' . $sessionId;
        }
    }
    return $baseString;
}

            
getAccessToken() public method
public Yiisoft\Yii\AuthClient\OAuthToken|null getAccessToken ( )
return Yiisoft\Yii\AuthClient\OAuthToken|null

Auth token instance.

                public function getAccessToken(): ?OAuthToken
{
    if (!is_object($this->accessToken)) {
        $this->accessToken = $this->restoreAccessToken();
    }
    return $this->accessToken;
}

            
getAuthParams() public method
public array getAuthParams ( )

                public function getAuthParams(): array
{
    return $this->authParams;
}

            
getClientId() public method
public string getClientId ( )

                public function getClientId(): string
{
    return $this->clientId;
}

            
getClientSecret() public method
public string getClientSecret ( )

                public function getClientSecret(): string
{
    return $this->clientSecret;
}

            
getConfigParam() public method

Returns particular configuration parameter value.

public mixed getConfigParam ( string $name )
$name string

Configuration parameter name.

return mixed

Configuration parameter value.

throws Yiisoft\Yii\AuthClient\Exception\InvalidConfigException
throws \Psr\SimpleCache\InvalidArgumentException

                public function getConfigParam(string $name): mixed
{
    $params = $this->getConfigParams();
    return $params[$name] ?? null;
}

            
getConfigParams() public method

public array getConfigParams ( )
return array

OpenID provider configuration parameters.

throws Yiisoft\Yii\AuthClient\Exception\InvalidConfigException
throws \Psr\SimpleCache\InvalidArgumentException

                public function getConfigParams(): array
{
    if (empty($this->configParams)) {
        $cacheKey = $this->cacheKeyPrefix . $this->getName();
        $configParams = (array) $this->cache->get($cacheKey);
        if (empty($configParams)) {
            $configParams = $this->discoverConfig();
            $this->cache->set($cacheKey, $configParams);
        }
        $this->configParams = $configParams;
    }
    return $this->configParams;
}

            
getCurrentUserJsonArray() public method

public array getCurrentUserJsonArray ( Yiisoft\Yii\AuthClient\OAuthToken $oauthToken )
$oauthToken Yiisoft\Yii\AuthClient\OAuthToken

                public function getCurrentUserJsonArray(OAuthToken $oauthToken): array
{
    return $this->fetchCurrentUserJsonArray($oauthToken, (string) $this->getConfigParam('userinfo_endpoint'));
}

            
getDefaultScope() protected method
protected string getDefaultScope ( )

                protected function getDefaultScope(): string
{
    return '';
}

            
getJwkSet() protected method

protected ?\Jose\Component\Core\JWKSet getJwkSet ( )

                protected function getJwkSet(): ?JWKSet
{
    if ($this->jwkSet instanceof JWKSet) {
        return $this->jwkSet;
    }
    $cacheKey = $this->cacheKeyPrefix . 'jwkSet';
    /** @var mixed $jwkSetRaw */
    $jwkSetRaw = $this->cache->get($cacheKey);
    /** @var JWKSet|null $jwkSet */
    $jwkSet = $jwkSetRaw instanceof JWKSet ? $jwkSetRaw : null;
    if ($jwkSet === null) {
        /** @var mixed $jwksUriRaw */
        $jwksUriRaw = $this->getConfigParam('jwks_uri');
        $jwksUri = is_string($jwksUriRaw) ? $jwksUriRaw : '';
        $request = $this->createRequest('GET', $jwksUri);
        $response = $this->sendRequest($request);
        /** @var mixed $jsonBody */
        $jsonBody = Json::decode($response->getBody()->getContents());
        $jsonBody = is_array($jsonBody) ? $jsonBody : [];
        /** @var mixed $fetched */
        $fetched = JWKFactory::createFromValues($jsonBody);
        $this->cache->set($cacheKey, $fetched);
        // JWKFactory::createFromValues() may return a plain JWK (single-key response)
        // instead of a JWKSet; $this->jwkSet is strictly typed, so only a real JWKSet is kept.
        $jwkSet = $fetched instanceof JWKSet ? $fetched : null;
    }
    if ($jwkSet instanceof JWKSet) {
        $this->jwkSet = $jwkSet;
    }
    return $jwkSet;
}

            
getJwsLoader() protected method

Returns the JWSLoader that validates the JWS token.

protected \Jose\Component\Signature\JWSLoader getJwsLoader ( )
return \Jose\Component\Signature\JWSLoader

To do token validation.

throws Yiisoft\Yii\AuthClient\Exception\InvalidConfigException

on an invalid algorithm provided in the configuration.

                protected function getJwsLoader(): JWSLoader
{
    if (!($this->jwsLoader instanceof JWSLoader)) {
        $algorithms = [];
        /** @var string $algorithm */
        foreach ($this->allowedJwsAlgorithms as $algorithm) {
            /** @var class-string<Algorithm> $class */
            $class = '\Jose\Component\Signature\Algorithm\\' . $algorithm;
            if (!class_exists($class)) {
                throw new InvalidConfigException("Algorithm class $class doesn't exist");
            }
            $algorithms[] = new $class();
        }
        $algorithmManager = new AlgorithmManager($algorithms);
        $compactSerializer = new CompactSerializer();
        /** @psalm-var string[] $this->allowedJwsAlgorithms */
        $checker = new AlgorithmChecker($this->allowedJwsAlgorithms);
        $this->jwsLoader = new JWSLoader(
            new JWSSerializerManager([$compactSerializer]),
            new JWSVerifier($algorithmManager),
            /**
             * @infection-ignore-all
             * $checker enforces the same $allowedJwsAlgorithms list that $algorithmManager above
             * is built from, so JWSVerifier already rejects any "alg" this checker would reject;
             * dropping it from the array is behaviorally unobservable from the outside.
             */
            new HeaderCheckerManager(
                [$checker],
                [new JWSTokenSupport()],
            ),
        );
    }
    return $this->jwsLoader;
}

            
getLogo() public method
public ?string getLogo ( )

getName() public method

public string getName ( )

                public function getName(): string
{
    return $this->name ?: 'openid-connect';
}

            
getNormalizeUserAttributeMap() public method
public array getNormalizeUserAttributeMap ( )
return array

Normalize user attribute map.

                public function getNormalizeUserAttributeMap(): array
{
    if (empty($this->normalizeUserAttributeMap)) {
        $this->normalizeUserAttributeMap = $this->defaultNormalizeUserAttributeMap();
    }
    return $this->normalizeUserAttributeMap;
}

            
getOauth2ReturnUrl() public method
public string getOauth2ReturnUrl ( )

                public function getOauth2ReturnUrl(): string
{
    return $this->returnUrl;
}

            
getRequestFactory() public method
public \Psr\Http\Message\RequestFactoryInterface getRequestFactory ( )

                public function getRequestFactory(): RequestFactoryInterface
{
    return $this->requestFactory;
}

            
getReturnUrl() public method
public string getReturnUrl ( \Psr\Http\Message\ServerRequestInterface $request )
$request \Psr\Http\Message\ServerRequestInterface
return string

Return URL.

                public function getReturnUrl(ServerRequestInterface $request): string
{
    if ($this->returnUrl === '') {
        $this->returnUrl = $this->defaultReturnUrl($request);
    }
    return $this->returnUrl;
}

            
getScope() public method
public string getScope ( )

                public function getScope(): string
{
    if ($this->scope === null) {
        return $this->getDefaultScope();
    }
    return $this->scope;
}

            
getSessionAuthState() public method

Defined in: Yiisoft\Yii\AuthClient\OAuth2::getSessionAuthState()

Compare a callback query parameter 'state' with the saved Auth Client's 'authState' parameter in order to prevent CSRF attacks

Use: Typically used in a AuthController's callback function specifically for an Identity Provider e.g. Facebook

public mixed getSessionAuthState ( )

                public function getSessionAuthState(): mixed
{
    /**
     * @see src\AuthClient protected function getState('authState')
     */
    return $this->getState('authState');
}

            
getState() protected method

Defined in: Yiisoft\Yii\AuthClient\AuthClient::getState()

Returns persistent state value.

protected mixed getState ( string $key )
$key string

State key.

return mixed

State value.

                protected function getState(string $key): mixed
{
    return $this->stateStorage->get($this->getStateKeyPrefix() . $key);
}

            
getStateKeyPrefix() protected method

Defined in: Yiisoft\Yii\AuthClient\AuthClient::getStateKeyPrefix()

Returns session key prefix, which is used to store internal states.

protected string getStateKeyPrefix ( )
return string

Session key prefix.

                protected function getStateKeyPrefix(): string
{
    return static::class . '_' . $this->getName() . '_';
}

            
getTitle() public method

public string getTitle ( )

                public function getTitle(): string
{
    if ($this->title !== '') {
        return $this->title;
    }
    return $this->name !== '' ? ucfirst($this->name) : 'OpenID Connect';
}

            
getTokenUrl() public method
public string getTokenUrl ( )

                public function getTokenUrl(): string
{
    return $this->tokenUrl;
}

            
getUserAttributes() public method

Defined in: Yiisoft\Yii\AuthClient\AuthClient::getUserAttributes()

Returns the authenticated user's attributes, as fetched by {@see initUserAttributes()} and normalized according to {@see normalizeUserAttributeMap}.

public array getUserAttributes ( )
return array

User attributes.

                public function getUserAttributes(): array
{
    $attributes = $this->initUserAttributes();
    $normalizeMap = $this->getNormalizeUserAttributeMap();
    return array_merge($attributes, $this->normalizeUserAttributes($attributes, $normalizeMap));
}

            
getValidateAuthNonce() public method

public boolean getValidateAuthNonce ( )
return boolean

Whether to use and validate auth 'nonce' parameter in authentication flow.

throws Yiisoft\Yii\AuthClient\Exception\InvalidConfigException
throws \Psr\SimpleCache\InvalidArgumentException

                public function getValidateAuthNonce(): bool
{
    if ($this->validateAuthNonce === null) {
        $this->validateAuthNonce = $this->validateJws && in_array(
            'nonce',
            (array) $this->getConfigParam('claims_supported'),
            true,
        );
    }
    return $this->validateAuthNonce;
}

            
getViewOptions() public method
public array getViewOptions ( )
return array

View options in format: optionName => optionValue

                public function getViewOptions(): array
{
    if (empty($this->viewOptions)) {
        $this->viewOptions = $this->defaultViewOptions();
    }
    return $this->viewOptions;
}

            
getYiisoftFactory() public method
public \Yiisoft\Factory\Factory getYiisoftFactory ( )

                public function getYiisoftFactory(): YiisoftFactory
{
    return $this->factory;
}

            
initUserAttributes() protected method

protected array initUserAttributes ( )

                protected function initUserAttributes(): array
{
    $token = $this->getAccessToken();
    if ($token instanceof OAuthToken) {
        return $this->getCurrentUserJsonArray($token);
    }
    return [];
}

            
loadJws() protected method

Decrypts/validates JWS, returning related data.

protected array loadJws ( string $jws )
$jws string

Raw JWS input.

return array

JWS underlying data.

throws Yiisoft\Yii\AuthClient\Exception\ClientException

on invalid JWS signature.

                protected function loadJws(string $jws): array
{
    try {
        $jwsLoader = $this->getJwsLoader();
        $signature = null;
        $jwkSet = $this->getJwkSet();
        if ($jwkSet === null) {
            throw new ClientException('JWK Set is not available.', 400);
        }
        $jwsVerified = $jwsLoader->loadAndVerifyWithKeySet($jws, $jwkSet, $signature);
        return (array) Json::decode((string) $jwsVerified->getPayload());
    } catch (Exception $e) {
        throw new ClientException('Loading JWS: Exception: ' . $e->getMessage(), (int) $e->getCode());
    }
}

            
refreshAccessToken() public method

public Yiisoft\Yii\AuthClient\OAuthToken refreshAccessToken ( Yiisoft\Yii\AuthClient\OAuthToken $token )
$token Yiisoft\Yii\AuthClient\OAuthToken

                public function refreshAccessToken(OAuthToken $token): OAuthToken
{
    $this->resolveTokenUrl();
    return parent::refreshAccessToken($token);
}

            
removeState() protected method

Defined in: Yiisoft\Yii\AuthClient\AuthClient::removeState()

Removes persistent state value.

protected void removeState ( string $key )
$key string

State key.

                protected function removeState(string $key): void
{
    $this->stateStorage->remove($this->getStateKeyPrefix() . $key);
}

            
restoreAccessToken() protected method

Defined in: Yiisoft\Yii\AuthClient\OAuth::restoreAccessToken()

Restores access token.

protected Yiisoft\Yii\AuthClient\OAuthToken|null restoreAccessToken ( )

                protected function restoreAccessToken(): ?OAuthToken
{
    if (($token = $this->getState('token')) instanceof OAuthToken) {
        if ($token->getIsExpired() && $this->autoRefreshAccessToken) {
            return $this->refreshAccessToken($token);
        }
        return $token;
    }
    return null;
}

            
saveAccessToken() protected method

Defined in: Yiisoft\Yii\AuthClient\OAuth::saveAccessToken()

Saves token as persistent state.

protected $this saveAccessToken ( Yiisoft\Yii\AuthClient\OAuthToken|null $token null )
$token Yiisoft\Yii\AuthClient\OAuthToken|null

Auth token to be saved.

return $this

The object itself.

                protected function saveAccessToken(?OAuthToken $token = null): self
{
    return $this->setState('token', $token);
}

            
sendRequest() protected method
protected \Psr\Http\Message\ResponseInterface sendRequest ( \Psr\Http\Message\RequestInterface $request )
$request \Psr\Http\Message\RequestInterface

                protected function sendRequest(RequestInterface $request): ResponseInterface
{
    return $this->httpClient->sendRequest($request);
}

            
setAccessToken() public method

Defined in: Yiisoft\Yii\AuthClient\OAuth::setAccessToken()

Sets access token to be used.

public void setAccessToken ( array|Yiisoft\Yii\AuthClient\OAuthToken $token )
$token array|Yiisoft\Yii\AuthClient\OAuthToken

Access token or its configuration.

                public function setAccessToken(array|OAuthToken $token): void
{
    if (is_array($token) && !empty($token)) {
        $newToken = $this->createToken($token);
        $this->accessToken = $newToken;
        $this->saveAccessToken($newToken);
    }
    if ($token instanceof OAuthToken) {
        $this->accessToken = $token;
        $this->saveAccessToken($token);
    }
}

            
setAuthParams() public method
public void setAuthParams ( array $authParams )
$authParams array

                public function setAuthParams(array $authParams): void
{
    $this->authParams = $authParams;
}

            
setAuthUrl() public method
public void setAuthUrl ( string $authUrl )
$authUrl string

                public function setAuthUrl(string $authUrl): void
{
    $this->authUrl = $authUrl;
}

            
setClientId() public method
public void setClientId ( string $clientId )
$clientId string

                public function setClientId(string $clientId): void
{
    $this->clientId = $clientId;
}

            
setClientSecret() public method
public void setClientSecret ( string $clientSecret )
$clientSecret string

                public function setClientSecret(string $clientSecret): void
{
    $this->clientSecret = $clientSecret;
}

            
setEnvironment() public method
public void setEnvironment ( string $devOrProd )
$devOrProd string

                public function setEnvironment(string $devOrProd): void
{
    $this->environment = $devOrProd;
}

            
setIssuerUrl() public method

public void setIssuerUrl ( string $url )
$url string

                public function setIssuerUrl(string $url): void
{
    $this->issuerUrl = rtrim($url, '/');
}

            
setLogo() public method
public void setLogo ( ?string $logo )
$logo ?string

setName() public method
public void setName ( string $name )
$name string

                public function setName(string $name): void
{
    $this->name = $name;
}

            
setOauth2ReturnUrl() public method
public void setOauth2ReturnUrl ( string $returnUrl )
$returnUrl string

                public function setOauth2ReturnUrl(string $returnUrl): void
{
    $this->returnUrl = $returnUrl;
}

            
setRequestFactory() public method
public void setRequestFactory ( \Psr\Http\Message\RequestFactoryInterface $requestFactory )
$requestFactory \Psr\Http\Message\RequestFactoryInterface

                public function setRequestFactory(RequestFactoryInterface $requestFactory): void
{
    $this->requestFactory = $requestFactory;
}

            
setReturnUrl() public method
public void setReturnUrl ( string $returnUrl )
$returnUrl string

Return URL

                public function setReturnUrl(string $returnUrl): void
{
    $this->returnUrl = $returnUrl;
}

            
setScope() public method
public void setScope ( string $scope )
$scope string

Auth request scope, overriding {@see \Yiisoft\Yii\AuthClient\getDefaultScope()}.

                public function setScope(string $scope): void
{
    $this->scope = $scope;
}

            
setState() protected method

Defined in: Yiisoft\Yii\AuthClient\AuthClient::setState()

Sets persistent state.

protected $this setState ( string $key, mixed $value )
$key string

State key.

$value mixed

State value

return $this

The object itself

                protected function setState(string $key, $value): self
{
    $this->stateStorage->set($this->getStateKeyPrefix() . $key, $value);
    return $this;
}

            
setTitle() public method
public void setTitle ( string $title )
$title string

                public function setTitle(string $title): void
{
    $this->title = $title;
}

            
setTokenUrl() public method
public void setTokenUrl ( string $tokenUrl )
$tokenUrl string

                public function setTokenUrl(string $tokenUrl): void
{
    $this->tokenUrl = $tokenUrl;
}

            
setValidateAuthNonce() public method

public void setValidateAuthNonce ( boolean $validateAuthNonce )
$validateAuthNonce boolean

                public function setValidateAuthNonce(bool $validateAuthNonce): void
{
    $this->validateAuthNonce = $validateAuthNonce;
}

            
setYiisoftFactory() public method
public void setYiisoftFactory ( \Yiisoft\Factory\Factory $factory )
$factory \Yiisoft\Factory\Factory

                public function setYiisoftFactory(YiisoftFactory $factory): void
{
    $this->factory = $factory;
}

            
validateClaims() protected method

Validates the claims data received from the OpenID provider.

protected void validateClaims ( array $claims )
$claims array

Claims data.

throws Yiisoft\Yii\AuthClient\Exception\ClientException

on invalid claims.

                protected function validateClaims(array $claims): void
{
    $iss = isset($claims['iss']) ? (string) $claims['iss'] : '';
    $issuerUrl = $this->issuerUrl;
    if (!isset($claims['iss']) || strcmp(rtrim($iss, '/'), rtrim($issuerUrl, '/')) !== 0) {
        throw new ClientException('Invalid "iss"', 400);
    }
    try {
        // "aud" may legally be a string or an array of strings (RFC 7519 §4.1.3); AudienceChecker
        // handles both, unlike a plain string comparison which would reject a valid array audience.
        (new AudienceChecker($this->clientId))->checkClaim($claims['aud'] ?? null);
    } catch (InvalidClaimException) {
        throw new ClientException('Invalid "aud"', 400);
    }
}

            
withValidateAuthState() public method
public self withValidateAuthState ( )

                public function withValidateAuthState(): self
{
    $new = clone $this;
    $new->validateAuthState = true;
    return $new;
}

            
withValidateJws() public method

Enables JWS validation/decryption of the auth token (the default). See {@see validateJws} for details.

public self withValidateJws ( )

                public function withValidateJws(): self
{
    $new = clone $this;
    $new->validateJws = true;
    return $new;
}

            
withoutValidateAuthState() public method
public self withoutValidateAuthState ( )

                public function withoutValidateAuthState(): self
{
    $new = clone $this;
    $new->validateAuthState = false;
    return $new;
}

            
withoutValidateJws() public method

Disables JWS validation/decryption of the auth token. See {@see validateJws} for the trade-offs of doing so.

public self withoutValidateJws ( )

                public function withoutValidateJws(): self
{
    $new = clone $this;
    $new->validateJws = false;
    return $new;
}