| Age | Commit message (Collapse) | Author | Files | Lines | |
|---|---|---|---|---|---|
| 2015-02-09 | [php5.2] Make validateRedirectUri protected to be able to override | Niko Sams | 1 | -1/+1 | |
| Like #512 for develop branch. This change is aginst php5.2-develop. I'm not sure if this branch is still active, nevertheless I have to use it on our SLES 10 Server with Php 5.2. | |||||
| 2013-06-13 | addresses #156 - documents required user_id for authcodes | Brent Shaffer | 1 | -0/+1 | |
| 2013-06-13 | addresses #157 for php5.2 | Brent Shaffer | 1 | -2/+2 | |
| 2013-06-11 | fixes #154 - adds getParameter to OAuth2_ResponseInterface | Brent Shaffer | 1 | -0/+2 | |
| 2013-06-11 | ensures invalid_token is returned according to ↵ | Brent Shaffer | 1 | -3/+3 | |
| http://tools.ietf.org/html/rfc6750#section-3.1 | |||||
| 2013-06-01 | standardizes error messages by removing period on scope and redirect errors | Brent Shaffer | 2 | -2/+2 | |
| 2013-06-01 | fixes #134 - allows for client_secret to be empty in post body if the client ↵ | Brent Shaffer | 1 | -2/+6 | |
| secret is an empty string | |||||
| 2013-06-01 | adds convenience getters/setters onto the server class (for real) | Brent Shaffer | 1 | -0/+50 | |
| 2013-06-01 | adds convenience getters/setters onto the server class | Brent Shaffer | 1 | -1/+2 | |
| 2013-05-30 | removes unnecessary isset | Brent Shaffer | 1 | -1/+1 | |
| 2013-05-30 | addresses #143 - adds WWW-Authenticate to 400 responses, removes error codes ↵ | Brent Shaffer | 2 | -23/+22 | |
| from invalid requests | |||||
| 2013-05-30 | addresses #145 - fixes status code for insufficient_scope requests | Brent Shaffer | 1 | -3/+6 | |
| 2013-05-30 | fixes formatting from #142, fixes same issue in a different spot | Brent Shaffer | 1 | -8/+18 | |
| 2013-05-29 | adds scopeutil constructor doc block | Brent Shaffer | 1 | -0/+4 | |
| 2013-05-29 | fixes #144 - correct mimeType parsing in header | Brent Shaffer | 1 | -1/+6 | |
| 2013-05-29 | Fix 401 response from ResourceController | Robbie Mackay | 1 | -3/+8 | |
| * Add missing s on %s to make sure we return realm value. * Add error and error_description to WWW-Authenticate header per http://tools.ietf.org/html/rfc6750#section-3 * Remove wrong error_uri parameter return because of extra params passed to setError() | |||||
| 2013-05-29 | adds interface methods to CompatibilityInterface | Brent Shaffer | 1 | -1/+2 | |
| 2013-05-29 | Merge pull request #140 from rjmackay/fix-resource-request-error | Brent Shaffer | 1 | -0/+5 | |
| Ensures resource request errors not overwritten by the insufficient_scope erro | |||||
| 2013-05-29 | Return from verifyResourceRequest() if we don't have token data | Robbie Mackay | 1 | -0/+5 | |
| This ensures any error response already set in getAccessTokenData gets returned, not overwritten by the 'insufficient_scope' error. | |||||
| 2013-05-28 | attempts to standardize documentation a little better | Brent Shaffer | 9 | -49/+41 | |
| 2013-05-28 | ** BC-BREAKING CHANGE ** - addresses #139 - makes ↵ | Brent Shaffer | 1 | -2/+5 | |
| OAuth2_Storage_UserCredentialsInterface::getUserDetails required to return user_id | |||||
| 2013-05-28 | ** BC-BREAKING CHANGE ** - addresses #80: hardens default security by making ↵ | Brent Shaffer | 2 | -2/+23 | |
| 'enforce_state' param in AuthorizationServer true by default | |||||
| 2013-05-28 | ** BC-BREAKING CHANGE ** - addresses #80: requires exact matching of URL by ↵ | Brent Shaffer | 2 | -4/+14 | |
| default, rather than only matching the beginning string | |||||
| 2013-05-28 | cleans up redirect URI validation | Brent Shaffer | 1 | -28/+34 | |
| 2013-05-26 | fixes #27 - adds way to pass in custom clientassertiontype to server object | Brent Shaffer | 1 | -11/+21 | |
| 2013-05-25 | adds ability to pass headers explicitly to Request object | Brent Shaffer | 1 | -4/+5 | |
| 2013-05-25 | fixes #137 - allows for multiple request_uris and adds tests for this | Brent Shaffer | 2 | -3/+17 | |
| 2013-05-21 | fixes hardcoded error message in TokenController, adds test coverage for ↵ | Brent Shaffer | 1 | -1/+1 | |
| error case | |||||
| 2013-05-16 | standardizes doc blocks | Brent Shaffer | 32 | -67/+153 | |
| 2013-05-13 | fixes spacing issues (psr2) | Brent Shaffer | 1 | -3/+2 | |
| 2013-05-13 | Merge pull request #125 from F21/token_controller_client_id_scope_exists | Brent Shaffer | 2 | -2/+13 | |
| TokenController now passes clientId into scopeExists(). | |||||
| 2013-05-13 | TokenController now passes clientId into scopeExists(). Tests have been | F21 | 2 | -2/+13 | |
| added for this. | |||||
| 2013-05-13 | improves documentation for addStorage function | Brent Shaffer | 1 | -3/+10 | |
| 2013-05-13 | fixes typehint for setAuthorizeController | Brent Shaffer | 1 | -1/+1 | |
| 2013-05-09 | rolling back OAuth2_Server fix due to php5.2 interface incompatibilities | Brent Shaffer | 1 | -6/+6 | |
| 2013-05-09 | better name for variables in AuthorizeController | Brent Shaffer | 1 | -2/+2 | |
| 2013-05-09 | adds defaults for OAuth2_Response objects back to the server class | Brent Shaffer | 3 | -20/+27 | |
| 2013-05-09 | cherry-picks redis class | 大兵 | 2 | -1/+196 | |
| 2013-05-09 | fixes fatal error and adds test to catch it next time | Brent Shaffer | 1 | -1/+1 | |
| 2013-05-09 | allows for injection of tokenType into the server object | Brent Shaffer | 1 | -26/+24 | |
| 2013-05-09 | ** BC-BREAKING CHANGES ** - changes TokenController constructor so ↵ | Brent Shaffer | 2 | -11/+20 | |
| ClientAssertionType is now the third parameter instead of the first, and it no longer accepts Storage_ClientCredentials, but has to be ClientAssertionTypeInterface | |||||
| 2013-05-09 | adds 'createDefault' methods for all controllers - more accurate naming of ↵ | Brent Shaffer | 1 | -32/+47 | |
| functions | |||||
| 2013-05-09 | adds setters for controller classes, standardises order of the controller ↵ | Brent Shaffer | 1 | -85/+112 | |
| classes, moves protected methods to bottom | |||||
| 2013-05-09 | ** BC-BREAKING CHANGE - accessTokenResponseType parameter in server class is ↵ | Brent Shaffer | 1 | -22/+18 | |
| redundant. This can be derived from the responseType parameter already passed in. Getting rid of it | |||||
| 2013-05-09 | updates readme and docblocks for response refactor | Brent Shaffer | 3 | -5/+10 | |
| 2013-05-09 | fixes variable names | Brent Shaffer | 1 | -2/+2 | |
| 2013-05-06 | fixes php 5.2 issue with interfaces sharing method names | Brent Shaffer | 3 | -6/+29 | |
| 2013-05-06 | cleans up ResponseInterface | Brent Shaffer | 4 | -11/+12 | |
| 2013-05-06 | BC-BREAKING CHANGE - Updates AuthorizeControllerInterface, ResponseInterface | Brent Shaffer | 11 | -185/+45 | |
| 2013-05-05 | BCBREAKING CHANGE - Updates to AuthorizeControllerInterface, ↵ | Brent Shaffer | 7 | -55/+41 | |
| ResourceControllerInterface, TokenTypeInterface | |||||
