heiglandreas /
HybridAuth
This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include, or for example
via PHP's auto-loading mechanism.
These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
| 1 | <?php |
||
| 2 | /** |
||
| 3 | * Copyright (c)2012-2012 heiglandreas |
||
| 4 | * |
||
| 5 | * Permission is hereby granted, free of charge, to any person obtaining a copy |
||
| 6 | * of this software and associated documentation files (the "Software"), to deal |
||
| 7 | * in the Software without restriction, including without limitation the rights |
||
| 8 | * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell |
||
| 9 | * copies of the Software, and to permit persons to whom the Software is |
||
| 10 | * furnished to do so, subject to the following conditions: |
||
| 11 | * |
||
| 12 | * The above copyright notice and this permission notice shall be included in |
||
| 13 | * all copies or substantial portions of the Software. |
||
| 14 | * |
||
| 15 | * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR |
||
| 16 | * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, |
||
| 17 | * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE |
||
| 18 | * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER |
||
| 19 | * LIBILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, |
||
| 20 | * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN |
||
| 21 | * THE SOFTWARE. |
||
| 22 | * |
||
| 23 | * @category |
||
| 24 | * @author Andreas Heigl<[email protected]> |
||
| 25 | * @copyright ©2012-2012 Andreas Heigl |
||
| 26 | * @license http://www.opesource.org/licenses/mit-license.php MIT-License |
||
| 27 | * @version 0.0 |
||
| 28 | * @since 27.12.12 |
||
| 29 | * @link https://github.com/heiglandreas/ |
||
| 30 | */ |
||
| 31 | namespace OrgHeiglHybridAuth\Controller; |
||
| 32 | |||
| 33 | use Hybridauth\Hybridauth; |
||
| 34 | use Hybridauth\Endpoint; |
||
| 35 | use SocialConnect\Auth\Service; |
||
| 36 | use Zend\Mvc\Controller\AbstractActionController; |
||
| 37 | use Zend\Session\Container as SessionContainer; |
||
| 38 | use OrgHeiglHybridAuth\UserWrapperFactory; |
||
| 39 | |||
| 40 | /** |
||
| 41 | * Login or out using a social service |
||
| 42 | * |
||
| 43 | * @category |
||
| 44 | * @author Andreas Heigl<[email protected]> |
||
| 45 | * @copyright ©2012-2012 Andreas Heigl |
||
| 46 | * @license http://www.opesource.org/licenses/mit-license.php MIT-License |
||
| 47 | * @version 0.0 |
||
| 48 | * @since 27.12.12 |
||
| 49 | * @link https://github.com/heiglandreas/ |
||
| 50 | */ |
||
| 51 | class IndexController extends AbstractActionController |
||
| 52 | { |
||
| 53 | /** |
||
| 54 | * Stores the HybridAuth-Instance |
||
| 55 | * |
||
| 56 | * @var Service $authenticator |
||
| 57 | */ |
||
| 58 | protected $authenticator = null; |
||
| 59 | |||
| 60 | /** |
||
| 61 | * Storage of the session-Container |
||
| 62 | * |
||
| 63 | * @var SessionContainer $session |
||
| 64 | */ |
||
| 65 | protected $session = null; |
||
| 66 | |||
| 67 | /** |
||
| 68 | * Storage of the UserProxyFactory |
||
| 69 | * |
||
| 70 | * @var UserWrapperFactory $userProxyFactory |
||
| 71 | */ |
||
| 72 | protected $userWrapperFactory = null; |
||
| 73 | /** |
||
| 74 | * Set the authenticator |
||
| 75 | * |
||
| 76 | * @param Service $authenticator The Authenticator-Backend |
||
| 77 | * |
||
| 78 | * @return IndexController |
||
| 79 | */ |
||
| 80 | public function setAuthenticator(Service $authenticator) |
||
| 81 | { |
||
| 82 | $this->authenticator = $authenticator; |
||
| 83 | return $this; |
||
| 84 | } |
||
| 85 | |||
| 86 | /** |
||
| 87 | * Set the session container |
||
| 88 | * |
||
| 89 | * @param SessionContainer $container The session-container to use for storing the authentication |
||
| 90 | * |
||
| 91 | * @return IndexController |
||
| 92 | */ |
||
| 93 | public function setSession(SessionContainer $container) |
||
| 94 | { |
||
| 95 | $this->session = $container; |
||
| 96 | return $this; |
||
| 97 | } |
||
| 98 | |||
| 99 | /** |
||
| 100 | * Set the userwrapper |
||
| 101 | * |
||
| 102 | * @param UserWrapperFactory $factory The ProxyFactory |
||
| 103 | * |
||
| 104 | * @return IndexController |
||
| 105 | */ |
||
| 106 | public function setUserWrapperFactory(UserWrapperFactory $factory) |
||
| 107 | { |
||
| 108 | $this->userWrapperFactory = $factory; |
||
| 109 | return $this; |
||
| 110 | } |
||
| 111 | |||
| 112 | /** |
||
| 113 | * login using twitter |
||
| 114 | */ |
||
| 115 | public function loginAction() |
||
| 116 | { |
||
| 117 | $providerName = $this->params()->fromRoute('provider'); |
||
| 118 | $this->session->offsetSet('redirect', $this->params()->fromRoute('redirect')); |
||
| 119 | |||
| 120 | $provider = $this->authenticator->getProvider($providerName); |
||
| 121 | |||
| 122 | return $this->redirectTo($provider->makeAuthUrl()); |
||
| 123 | } |
||
| 124 | |||
| 125 | /** |
||
| 126 | * Logout |
||
| 127 | */ |
||
| 128 | public function logoutAction() |
||
| 129 | { |
||
| 130 | $this->session->offsetSet('authenticated', false); |
||
| 131 | $this->session->offsetSet('user', null); |
||
| 132 | $this->session->offsetSet('backend', null); |
||
| 133 | |||
| 134 | return $this->doRedirect(); |
||
| 135 | } |
||
| 136 | |||
| 137 | /** |
||
| 138 | * Redirect to the last known URL |
||
| 139 | * |
||
| 140 | * @return boolean |
||
| 141 | */ |
||
| 142 | protected function doRedirect() |
||
| 143 | { |
||
| 144 | if (! $redirect = $this->session->offsetGet('redirect')) { |
||
| 145 | $redirect = $this->getEvent()->getRouteMatch()->getParam('redirect'); |
||
| 146 | } |
||
| 147 | |||
| 148 | $this->session->offsetUnset('redirect'); |
||
| 149 | $redirect = base64_decode($redirect); |
||
| 150 | |||
| 151 | if (! $redirect) { |
||
| 152 | $redirect = '/'; |
||
| 153 | } |
||
| 154 | |||
| 155 | if (preg_match('|://|', $redirect)) { |
||
| 156 | $this->redirect()->toUrl($redirect); |
||
| 157 | } else { |
||
| 158 | $this->redirect()->toRoute($redirect); |
||
| 159 | } |
||
| 160 | return false; |
||
| 161 | } |
||
| 162 | |||
| 163 | public function redirectTo($uri) |
||
| 164 | { |
||
| 165 | $this->redirect()->toUrl($uri); |
||
| 166 | } |
||
| 167 | |||
| 168 | /** |
||
| 169 | * Call the HybridAuth-Backend |
||
| 170 | */ |
||
| 171 | public function backendAction() |
||
|
0 ignored issues
–
show
|
|||
| 172 | { |
||
| 173 | $providerName = $this->params()->fromRoute('provider'); |
||
| 174 | |||
| 175 | $provider = $this->authenticator->getProvider($providerName); |
||
| 176 | $accessToken = $provider->getAccessTokenByRequestParameters($_GET); |
||
| 177 | |||
| 178 | if (! $accessToken) { |
||
| 179 | $this->session->offsetSet('authenticated', false); |
||
| 180 | $this->session->offsetSet('user', null); |
||
| 181 | $this->session->offsetSet('backend', $providerName); |
||
| 182 | |||
| 183 | return $this->doRedirect(); |
||
| 184 | } |
||
| 185 | |||
| 186 | $this->session->offsetSet('authenticated',true); |
||
| 187 | $this->session->offsetSet('user', $this->userWrapperFactory->factory($provider->getIdentity($accessToken))); |
||
| 188 | $this->session->offsetSet('backend', $providerName); |
||
| 189 | |||
| 190 | return $this->doRedirect(); |
||
| 191 | } |
||
| 192 | } |
||
| 193 |
Instead of super-globals, we recommend to explicitly inject the dependencies of your class. This makes your code less dependent on global state and it becomes generally more testable: