| Age | Commit message (Collapse) | Author | Files | Lines | |
|---|---|---|---|---|---|
| 2013-07-24 | fixes #194 - makes some appropriate properties protected instead of private | Brent Shaffer | 11 | -30/+33 | |
| 2013-07-16 | fixes #191 - passes config to HttpBasic | Brent Shaffer | 1 | -1/+3 | |
| 2013-07-15 | fixes #190 - validates client credentials before grant type | Brent Shaffer | 1 | -6/+14 | |
| 2013-07-13 | Merge pull request #171 from davidkuridza/fix-redirect-in-authorization-flow | Brent Shaffer | 1 | -1/+13 | |
| Fix wrong redirect following authorization step | |||||
| 2013-07-08 | client_id is now passed to getDefaultScope(). | F21 | 5 | -7/+14 | |
| 2013-07-06 | Fix wrong redirect following authorization step, refs #171 | David Kuridža | 1 | -1/+13 | |
| Fix for #163 (https://github.com/bshaffer/oauth2-server-php/issues/163) allowed authorize flow to handle `redirect_uri` as an optional parameter. The change resulted in user not being redirected back to the client after granting or denying client's access. This fix verifies whether `redirect_uri` is set or not in `OAuth2\Controller\AuthorizeController`'s `handleAuthorizeRequest()` method. If it's not set, it grabs the client's registered value. If/When support for PHP 5.3 is dropped, the code can be modified to `$this->clientStorage->getClientDetails($this->client_id)['redirect_uri']`. | |||||
| 2013-07-04 | Update Mongo.php | Brent Shaffer | 1 | -3/+4 | |
| Fixes #185 - mongo credentials check | |||||
| 2013-07-03 | Update Redis.php | Brent Shaffer | 1 | -1/+1 | |
| Fixes #180 - case correction for JWTBearerInterface | |||||
| 2013-06-29 | Merge pull request #176 from trickleup/develop | Brent Shaffer | 1 | -0/+1 | |
| Require refresh_token in getRefreshToken response | |||||
| 2013-06-29 | Require refresh_token in getRefreshToken response | Johan Genberg | 1 | -1/+1 | |
| Added "identifier" to description. | |||||
| 2013-06-29 | Require refresh_token in getRefreshToken response | Johan Genberg | 1 | -0/+1 | |
| 2013-06-28 | Merge pull request #174 from trickleup/develop | Brent Shaffer | 1 | -1/+1 | |
| make user_id not required for refresh_token grant | |||||
| 2013-06-28 | make user_id not required for refresh_token grant | Johan Genberg | 1 | -1/+1 | |
| 2013-06-28 | Duplication in JwtBearer Grant | Trent Petersen | 1 | -5/+0 | |
| Corrects duplicate check in the validateRequest method found in #172 | |||||
| 2013-06-28 | user_id not required for authorization_code grant | Johan Genberg | 1 | -1/+1 | |
| 2013-06-23 | addresses #133 - hardens default security for user objects | Brent Shaffer | 1 | -1/+4 | |
| 2013-06-23 | fixes #162 - adds getToken on ResourceController for convenience | Brent Shaffer | 1 | -0/+10 | |
| 2013-06-23 | fixes #163 - only saves submitted redirect_uris to the authorization code, ↵ | Brent Shaffer | 1 | -8/+60 | |
| so no redirect_uri is properly handled in token controller. AuthorizeController->validateRequest now returns a boolean instead of params array. Parameters can be accessed using the new class getter functions | |||||
| 2013-06-23 | cleans up stupid rhetoric in comment | Brent Shaffer | 1 | -1/+1 | |
| 2013-06-13 | adds namespace back - seriously, don't merge from php 5.2 | Brent Shaffer | 1 | -0/+2 | |
| 2013-06-13 | fixes bug in class name- don't merge from php5.2 branch anymore.. | Brent Shaffer | 1 | -1/+1 | |
| 2013-06-13 | addresses #156 - documents required user_id for authcodes | Brent Shaffer | 1 | -3/+2 | |
| 2013-06-13 | Fix for extending access and refresh tokens | Miha Hribar | 1 | -2/+2 | |
| 2013-06-11 | fixes #154 - adds getParameter to OAuth2_ResponseInterface | Brent Shaffer | 1 | -0/+2 | |
| 2013-06-11 | ensures invalid_token is returned according to ↵ | Brent Shaffer | 1 | -3/+3 | |
| http://tools.ietf.org/html/rfc6750#section-3.1 | |||||
| 2013-06-06 | moves interfaces into namespaced classes | Brent Shaffer | 17 | -24/+23 | |
| 2013-06-05 | allows response to be null on Server methods | Brent Shaffer | 1 | -6/+6 | |
| 2013-06-02 | Rename JWTBearerInterface.php to JwtBearerInterface.php | Brent Shaffer | 1 | -0/+0 | |
| 2013-06-02 | Rename JWTBearer.php to JwtBearer.php | Brent Shaffer | 1 | -0/+0 | |
| 2013-06-02 | Rename JWT.php to Jwt.php | Brent Shaffer | 1 | -0/+0 | |
| 2013-06-02 | converts all classes to namespaces | Brent Shaffer | 44 | -217/+396 | |
| 2013-06-01 | standardizes error messages by removing period on scope and redirect errors | Brent Shaffer | 2 | -2/+2 | |
| 2013-06-01 | fixes #134 - allows for client_secret to be empty in post body if the client ↵ | Brent Shaffer | 1 | -2/+6 | |
| secret is an empty string | |||||
| 2013-06-01 | adds convenience getters/setters onto the server class (for real) | Brent Shaffer | 1 | -0/+50 | |
| 2013-06-01 | adds convenience getters/setters onto the server class | Brent Shaffer | 1 | -1/+2 | |
| 2013-05-30 | removes unnecessary isset | Brent Shaffer | 1 | -1/+1 | |
| 2013-05-30 | addresses #143 - adds WWW-Authenticate to 400 responses, removes error codes ↵ | Brent Shaffer | 2 | -23/+22 | |
| from invalid requests | |||||
| 2013-05-30 | addresses #145 - fixes status code for insufficient_scope requests | Brent Shaffer | 1 | -3/+6 | |
| 2013-05-30 | fixes formatting from #142, fixes same issue in a different spot | Brent Shaffer | 1 | -8/+18 | |
| 2013-05-29 | adds scopeutil constructor doc block | Brent Shaffer | 1 | -0/+4 | |
| 2013-05-29 | fixes #144 - correct mimeType parsing in header | Brent Shaffer | 1 | -1/+6 | |
| 2013-05-29 | Fix 401 response from ResourceController | Robbie Mackay | 1 | -3/+8 | |
| * Add missing s on %s to make sure we return realm value. * Add error and error_description to WWW-Authenticate header per http://tools.ietf.org/html/rfc6750#section-3 * Remove wrong error_uri parameter return because of extra params passed to setError() | |||||
| 2013-05-29 | adds interface methods to CompatibilityInterface | Brent Shaffer | 1 | -1/+2 | |
| 2013-05-29 | Merge pull request #140 from rjmackay/fix-resource-request-error | Brent Shaffer | 1 | -0/+5 | |
| Ensures resource request errors not overwritten by the insufficient_scope erro | |||||
| 2013-05-29 | Return from verifyResourceRequest() if we don't have token data | Robbie Mackay | 1 | -0/+5 | |
| This ensures any error response already set in getAccessTokenData gets returned, not overwritten by the 'insufficient_scope' error. | |||||
| 2013-05-28 | attempts to standardize documentation a little better | Brent Shaffer | 9 | -49/+41 | |
| 2013-05-28 | ** BC-BREAKING CHANGE ** - addresses #139 - makes ↵ | Brent Shaffer | 1 | -2/+5 | |
| OAuth2_Storage_UserCredentialsInterface::getUserDetails required to return user_id | |||||
| 2013-05-28 | ** BC-BREAKING CHANGE ** - addresses #80: hardens default security by making ↵ | Brent Shaffer | 2 | -2/+23 | |
| 'enforce_state' param in AuthorizationServer true by default | |||||
| 2013-05-28 | ** BC-BREAKING CHANGE ** - addresses #80: requires exact matching of URL by ↵ | Brent Shaffer | 2 | -4/+14 | |
| default, rather than only matching the beginning string | |||||
| 2013-05-28 | cleans up redirect URI validation | Brent Shaffer | 1 | -28/+34 | |
