summaryrefslogtreecommitdiff
path: root/src
AgeCommit message (Collapse)AuthorFilesLines
2013-07-24fixes #194 - makes some appropriate properties protected instead of privateBrent Shaffer11-30/+33
2013-07-16fixes #191 - passes config to HttpBasicBrent Shaffer1-1/+3
2013-07-15fixes #190 - validates client credentials before grant typeBrent Shaffer1-6/+14
2013-07-13Merge pull request #171 from davidkuridza/fix-redirect-in-authorization-flowBrent Shaffer1-1/+13
Fix wrong redirect following authorization step
2013-07-08client_id is now passed to getDefaultScope().F215-7/+14
2013-07-06Fix wrong redirect following authorization step, refs #171David Kuridža1-1/+13
Fix for #163 (https://github.com/bshaffer/oauth2-server-php/issues/163) allowed authorize flow to handle `redirect_uri` as an optional parameter. The change resulted in user not being redirected back to the client after granting or denying client's access. This fix verifies whether `redirect_uri` is set or not in `OAuth2\Controller\AuthorizeController`'s `handleAuthorizeRequest()` method. If it's not set, it grabs the client's registered value. If/When support for PHP 5.3 is dropped, the code can be modified to `$this->clientStorage->getClientDetails($this->client_id)['redirect_uri']`.
2013-07-04Update Mongo.phpBrent Shaffer1-3/+4
Fixes #185 - mongo credentials check
2013-07-03Update Redis.phpBrent Shaffer1-1/+1
Fixes #180 - case correction for JWTBearerInterface
2013-06-29Merge pull request #176 from trickleup/developBrent Shaffer1-0/+1
Require refresh_token in getRefreshToken response
2013-06-29Require refresh_token in getRefreshToken responseJohan Genberg1-1/+1
Added "identifier" to description.
2013-06-29Require refresh_token in getRefreshToken responseJohan Genberg1-0/+1
2013-06-28Merge pull request #174 from trickleup/developBrent Shaffer1-1/+1
make user_id not required for refresh_token grant
2013-06-28make user_id not required for refresh_token grantJohan Genberg1-1/+1
2013-06-28Duplication in JwtBearer GrantTrent Petersen1-5/+0
Corrects duplicate check in the validateRequest method found in #172
2013-06-28user_id not required for authorization_code grantJohan Genberg1-1/+1
2013-06-23addresses #133 - hardens default security for user objectsBrent Shaffer1-1/+4
2013-06-23fixes #162 - adds getToken on ResourceController for convenienceBrent Shaffer1-0/+10
2013-06-23fixes #163 - only saves submitted redirect_uris to the authorization code, ↵Brent Shaffer1-8/+60
so no redirect_uri is properly handled in token controller. AuthorizeController->validateRequest now returns a boolean instead of params array. Parameters can be accessed using the new class getter functions
2013-06-23cleans up stupid rhetoric in commentBrent Shaffer1-1/+1
2013-06-13adds namespace back - seriously, don't merge from php 5.2Brent Shaffer1-0/+2
2013-06-13fixes bug in class name- don't merge from php5.2 branch anymore..Brent Shaffer1-1/+1
2013-06-13addresses #156 - documents required user_id for authcodesBrent Shaffer1-3/+2
2013-06-13Fix for extending access and refresh tokensMiha Hribar1-2/+2
2013-06-11fixes #154 - adds getParameter to OAuth2_ResponseInterfaceBrent Shaffer1-0/+2
2013-06-11ensures invalid_token is returned according to ↵Brent Shaffer1-3/+3
http://tools.ietf.org/html/rfc6750#section-3.1
2013-06-06moves interfaces into namespaced classesBrent Shaffer17-24/+23
2013-06-05allows response to be null on Server methodsBrent Shaffer1-6/+6
2013-06-02Rename JWTBearerInterface.php to JwtBearerInterface.phpBrent Shaffer1-0/+0
2013-06-02Rename JWTBearer.php to JwtBearer.phpBrent Shaffer1-0/+0
2013-06-02Rename JWT.php to Jwt.phpBrent Shaffer1-0/+0
2013-06-02converts all classes to namespacesBrent Shaffer44-217/+396
2013-06-01standardizes error messages by removing period on scope and redirect errorsBrent Shaffer2-2/+2
2013-06-01fixes #134 - allows for client_secret to be empty in post body if the client ↵Brent Shaffer1-2/+6
secret is an empty string
2013-06-01adds convenience getters/setters onto the server class (for real)Brent Shaffer1-0/+50
2013-06-01adds convenience getters/setters onto the server classBrent Shaffer1-1/+2
2013-05-30removes unnecessary issetBrent Shaffer1-1/+1
2013-05-30addresses #143 - adds WWW-Authenticate to 400 responses, removes error codes ↵Brent Shaffer2-23/+22
from invalid requests
2013-05-30addresses #145 - fixes status code for insufficient_scope requestsBrent Shaffer1-3/+6
2013-05-30fixes formatting from #142, fixes same issue in a different spotBrent Shaffer1-8/+18
2013-05-29adds scopeutil constructor doc blockBrent Shaffer1-0/+4
2013-05-29fixes #144 - correct mimeType parsing in headerBrent Shaffer1-1/+6
2013-05-29Fix 401 response from ResourceControllerRobbie Mackay1-3/+8
* Add missing s on %s to make sure we return realm value. * Add error and error_description to WWW-Authenticate header per http://tools.ietf.org/html/rfc6750#section-3 * Remove wrong error_uri parameter return because of extra params passed to setError()
2013-05-29adds interface methods to CompatibilityInterfaceBrent Shaffer1-1/+2
2013-05-29Merge pull request #140 from rjmackay/fix-resource-request-errorBrent Shaffer1-0/+5
Ensures resource request errors not overwritten by the insufficient_scope erro
2013-05-29Return from verifyResourceRequest() if we don't have token dataRobbie Mackay1-0/+5
This ensures any error response already set in getAccessTokenData gets returned, not overwritten by the 'insufficient_scope' error.
2013-05-28attempts to standardize documentation a little betterBrent Shaffer9-49/+41
2013-05-28** BC-BREAKING CHANGE ** - addresses #139 - makes ↵Brent Shaffer1-2/+5
OAuth2_Storage_UserCredentialsInterface::getUserDetails required to return user_id
2013-05-28** BC-BREAKING CHANGE ** - addresses #80: hardens default security by making ↵Brent Shaffer2-2/+23
'enforce_state' param in AuthorizationServer true by default
2013-05-28** BC-BREAKING CHANGE ** - addresses #80: requires exact matching of URL by ↵Brent Shaffer2-4/+14
default, rather than only matching the beginning string
2013-05-28cleans up redirect URI validationBrent Shaffer1-28/+34