【问题标题】:Guide me implementing Oauth2 PHP server using thephpleague library指导我使用 phpleague 库实现 Oauth2 PHP 服务器
【发布时间】:2014-12-06 16:17:18
【问题描述】:

我正在使用Slim FrameworkEloquent ORM。试图实现https://github.com/thephpleague/oauth2-server,但我完全不知道如何做到这一点。用composer添加后,我用这个包中提供的sql文件创建了数据库。

现在建议implement Storage interfaces。我不想这样做,所以我只是复制了示例文件夹中的存储类。我想它们应该可以工作,因为我使用的是相同的数据库,对吧?

还不清楚如何最初为 db 播种。这是我的路由器,我正在尝试password 方法。

$server = new \League\OAuth2\Server\AuthorizationServer;

$server->setSessionStorage(new SessionStorage);
$server->setAccessTokenStorage(new AccessTokenStorage);
$server->setClientStorage(new ClientStorage);
$server->setScopeStorage(new ScopeStorage);

$passwordGrant = new \League\OAuth2\Server\Grant\PasswordGrant();
$passwordGrant->setVerifyCredentialsCallback(function ($username, $password) {
    // implement logic here to validate a username and password, return an ID if valid, otherwise return false
    return 1;
});

$server->addGrantType($passwordGrant);

$app->post('/token',function() use ($server,$app){
    try{
        $response = $server->issueAccessToken();

        $res = $app->response();
        $res['Content-Type'] = 'application/json';

        $res->body(json_encode($response));

    } catch (\Exception $e) {

       var_dump($e);
    }

});

我对发生的事情感到非常沮丧。 这会引发以下异常。 [我在 db 中添加了作用域ok]

object(League\OAuth2\Server\Exception\InvalidScopeException)[82]
  public 'httpStatusCode' => int 400
  public 'errorType' => string 'invalid_scope' (length=13)
  public 'serverShouldRedirect' => boolean true
  protected 'message' => string 'The requested scope is invalid, unknown, or malformed. Check the "ok" scope.' (length=76)
  private 'string' (Exception) => string '' (length=0)
  protected 'code' => int 0
  protected 'file' => string 'C:\wamp\www\linkshare\vendor\league\oauth2-server\src\Grant\AbstractGrant.php' (length=77)
  protected 'line' => int 163
  private 'trace' (Exception) => 
    array (size=11)
      0 => 
        array (size=6)
          'file' => string 'C:\wamp\www\linkshare\vendor\league\oauth2-server\src\Grant\PasswordGrant.php' (length=77)
          'line' => int 130
          'function' => string 'validateScopes' (length=14)
          'class' => string 'League\OAuth2\Server\Grant\AbstractGrant' (length=40)
          'type' => string '->' (length=2)
          'args' => 
            array (size=2)
              ...
      1 => 
        array (size=6)
          'file' => string 'C:\wamp\www\linkshare\vendor\league\oauth2-server\src\AuthorizationServer.php' (length=77)
          'line' => int 330
          'function' => string 'completeFlow' (length=12)
          'class' => string 'League\OAuth2\Server\Grant\PasswordGrant' (length=40)
          'type' => string '->' (length=2)
          'args' => 
            array (size=0)
              ...
      2 => 
        array (size=6)
          'file' => string 'C:\wamp\www\linkshare\index.php' (length=31)
          'line' => int 67
          'function' => string 'issueAccessToken' (length=16)
          'class' => string 'League\OAuth2\Server\AuthorizationServer' (length=40)
          'type' => string '->' (length=2)
          'args' => 
            array (size=0)
              ...
      3 => 
        array (size=2)
          'function' => string '{closure}' (length=9)
          'args' => 
            array (size=0)
              ...
      4 => 
        array (size=4)
          'file' => string 'C:\wamp\www\linkshare\vendor\slim\slim\Slim\Route.php' (length=53)
          'line' => int 462
          'function' => string 'call_user_func_array' (length=20)
          'args' => 
            array (size=2)
              ...
      5 => 
        array (size=6)
          'file' => string 'C:\wamp\www\linkshare\vendor\slim\slim\Slim\Slim.php' (length=52)
          'line' => int 1326
          'function' => string 'dispatch' (length=8)
          'class' => string 'Slim\Route' (length=10)
          'type' => string '->' (length=2)
          'args' => 
            array (size=0)
              ...
      6 => 
        array (size=6)
          'file' => string 'C:\wamp\www\linkshare\vendor\slim\slim\Slim\Middleware\Flash.php' (length=64)
          'line' => int 85
          'function' => string 'call' (length=4)
          'class' => string 'Slim\Slim' (length=9)
          'type' => string '->' (length=2)
          'args' => 
            array (size=0)
              ...
      7 => 
        array (size=6)
          'file' => string 'C:\wamp\www\linkshare\vendor\slim\slim\Slim\Middleware\MethodOverride.php' (length=73)
          'line' => int 92
          'function' => string 'call' (length=4)
          'class' => string 'Slim\Middleware\Flash' (length=21)
          'type' => string '->' (length=2)
          'args' => 
            array (size=0)
              ...
      8 => 
        array (size=6)
          'file' => string 'C:\wamp\www\linkshare\vendor\slim\slim\Slim\Middleware\PrettyExceptions.php' (length=75)
          'line' => int 67
          'function' => string 'call' (length=4)
          'class' => string 'Slim\Middleware\MethodOverride' (length=30)
          'type' => string '->' (length=2)
          'args' => 
            array (size=0)
              ...
      9 => 
        array (size=6)
          'file' => string 'C:\wamp\www\linkshare\vendor\slim\slim\Slim\Slim.php' (length=52)
          'line' => int 1271
          'function' => string 'call' (length=4)
          'class' => string 'Slim\Middleware\PrettyExceptions' (length=32)
          'type' => string '->' (length=2)
          'args' => 
            array (size=0)
              ...
      10 => 
        array (size=6)
          'file' => string 'C:\wamp\www\linkshare\index.php' (length=31)
          'line' => int 131
          'function' => string 'run' (length=3)
          'class' => string 'Slim\Slim' (length=9)
          'type' => string '->' (length=2)
          'args' => 
            array (size=0)

【问题讨论】:

    标签: php oauth eloquent slim thephpleague


    【解决方案1】:

    OAuth 2.0 很难正确理解和使用。事实上,OAuth 2.0 的领先者famously walked away from the protocol after years of developing for it。根据 Eran Hammer(上述首席开发人员)的说法:

    与 OAuth 1.0 相比,2.0 规范更加复杂, 互操作性较差、有用性较差、不完整且大多数 重要的是,不太安全。

    需要明确的是,OAuth 2.0 掌握在具有深度的开发人员手中 对网络安全的理解可能会导致安全 执行。然而,在大多数开发人员手中——正如 过去两年的经验——2.0可能会产生 不安全的实现。

    不用说,关于 OAuth 2.0 存在一些争论。 PHP League 的 OAuth 2.0-Server 框架的首席开发人员 Alex Bilbie 似乎是 OAuth 2.0 知识更丰富的开发人员之一,尽管毫无疑问还有更多。尽管如此,请记住 Hammer 的一大抱怨 - 缺乏互操作性和完整性 - 您可能希望在 OAuth 2.0 实现中寻找以下内容:

    • 积极发展
    • 完全符合 OAuth 2.0

    我个人使用并推荐 Alex Bilbie 的 OAuth 2.0-Server,它现在包含 MAC 不记名令牌,旨在完全兼容。它也在积极开发中。

    那么,这对您的项目意味着什么?阅读规格。我们使用的包声称完全兼容,这意味着您最好的资源是OAuth 2.0's specification 本身。 PHP League website 下也有不错的文档,可以帮助您进行此特定实现。

    话虽如此,您可能缺少客户/用户组合的范围。 OAuth2.0 的结构方式是,您的用户需要接受客户端请求的范围。这意味着您的“范围”需要在您的其他表中链接。如果“OK”没有被用户(在数据库中)批准,那么它将不会被批准。

    编辑

    听起来范围对您来说不是问题。该场所不太适合进行故障排除,因此我建议您确保拥有您选择使用的任何框架的最新版本,并向开发人员报告任何错误(使用 PHPLeague,它是通过 Github)。

    【讨论】:

    • 感谢您的详细解释。对我有很大帮助!
    • 我参加聚会有点晚了,但为什么这条评论被否决了?
    • 我讨厌 SA 的这个功能......人们可以在完全没有回应的情况下投反对票。非常被动进取,无法帮助提问者或回答者。我编辑了我的问题,希望它能解决人们不喜欢的问题。
    • @Mave 因为它并没有真正回答问题。任何人都可以复制粘贴一些文本,将您指向一本书和规格。提问者要求就他们所拥有的东西提供指导,而不是要求一些武断的“读这本书”的答案。
    【解决方案2】:

    问这个问题已经有好几年了,但这里是 Slim 3 的 OAuth2 库的链接:

    【讨论】:

      猜你喜欢
      • 2015-04-01
      • 1970-01-01
      • 1970-01-01
      • 2016-04-16
      • 2019-03-14
      • 1970-01-01
      • 2020-07-23
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多