. // }}} /** * OAuth2 implementation for GNU social * * @package OAuth2 * @category API * * @author Diogo Peralta Cordeiro * @author Hugo Sales * @copyright 2022 Free Software Foundation, Inc http://www.fsf.org * @license https://www.gnu.org/licenses/agpl.html GNU AGPL v3 or later */ namespace Plugin\OAuth2\Controller; use App\Core\Controller; use App\Entity\LocalUser; use App\Util\Exception\NotFoundException; use League\OAuth2\Server\Entities\UserEntityInterface; use League\OAuth2\Server\Exception\OAuthServerException; use Nyholm\Psr7\Factory\Psr17Factory; use Plugin\OAuth2\OAuth2; use Psr\Http\Message\ResponseFactoryInterface; use Symfony\Bridge\PsrHttpMessage\Factory\HttpFoundationFactory; use Symfony\Bridge\PsrHttpMessage\Factory\PsrHttpFactory; use Symfony\Component\HttpFoundation\JsonResponse; use Symfony\Component\HttpFoundation\Request; use Symfony\Component\HttpFoundation\RequestStack; class Authorize extends Controller { public function __construct( RequestStack $stack, private ResponseFactoryInterface $response_factory, ) { parent::__construct($stack); } public function __invoke(Request $request) { // @var \League\OAuth2\Server\AuthorizationServer $server $server = OAuth2::$authorization_server; $response = $this->response_factory->createResponse(); $httpFoundationFactory = new HttpFoundationFactory; try { // Validate the HTTP request and return an AuthorizationRequest object. // The auth request object can be serialized into a user's session $psr17Factory = new Psr17Factory(); $psrHttpFactory = new PsrHttpFactory($psr17Factory, $psr17Factory, $psr17Factory, $psr17Factory); $psrRequest = $psrHttpFactory->createRequest($request); $authRequest = $server->validateAuthorizationRequest($psrRequest); // TODO // Once the user has logged in set the user on the AuthorizationRequest $authRequest->setUser( new class(LocalUser::getByNickname('foo')->getId()) implements UserEntityInterface { public function __construct(private int $id) { } public function getIdentifier() { return $this->id; } }, ); // Once the user has approved or denied the client update the status // (true = approved, false = denied) $authRequest->setAuthorizationApproved(true); // Return the HTTP redirect response return $httpFoundationFactory->createResponse($server->completeAuthorizationRequest($authRequest, $response)); } catch (OAuthServerException $exception) { return $httpFoundationFactory->createResponse($exception->generateHttpResponse($response)); } catch (NotFoundException) { return new JsonResponse(['error' => 'No such client', 'error_description' => 'This client is not registered']); } } }