| 1 |
<?php |
| 2 |
/*! |
| 3 |
* This file is part of the OAuth PHP Library (https://code.google.com/p/oauth/) |
| 4 |
* |
| 5 |
* OAuth `PHP' Library is an open source software available under the MIT License. |
| 6 |
*/ |
| 7 |
|
| 8 |
namespace Hybridauth\Thirdparty\OAuth; |
| 9 |
|
| 10 |
/** |
| 11 |
* Class OAuthSignatureMethod |
| 12 |
* |
| 13 |
* @package Hybridauth\Thirdparty\OAuth |
| 14 |
*/ |
| 15 |
abstract class OAuthSignatureMethod |
| 16 |
{ |
| 17 |
/** |
| 18 |
* Needs to return the name of the Signature Method (ie HMAC-SHA1) |
| 19 |
* |
| 20 |
* @return string |
| 21 |
*/ |
| 22 |
abstract public function get_name(); |
| 23 |
|
| 24 |
/** |
| 25 |
* Build up the signature |
| 26 |
* NOTE: The output of this function MUST NOT be urlencoded. |
| 27 |
* the encoding is handled in OAuthRequest when the final |
| 28 |
* request is serialized |
| 29 |
* |
| 30 |
* @param OAuthRequest $request |
| 31 |
* @param OAuthConsumer $consumer |
| 32 |
* @param OAuthToken $token |
| 33 |
* @return string |
| 34 |
*/ |
| 35 |
abstract public function build_signature($request, $consumer, $token); |
| 36 |
|
| 37 |
/** |
| 38 |
* Verifies that a given signature is correct |
| 39 |
* |
| 40 |
* @param OAuthRequest $request |
| 41 |
* @param OAuthConsumer $consumer |
| 42 |
* @param OAuthToken $token |
| 43 |
* @param string $signature |
| 44 |
* @return bool |
| 45 |
*/ |
| 46 |
public function check_signature($request, $consumer, $token, $signature) |
| 47 |
{ |
| 48 |
$built = $this->build_signature($request, $consumer, $token); |
| 49 |
|
| 50 |
// Check for zero length, although unlikely here |
| 51 |
if (strlen($built) == 0 || strlen($signature) == 0) { |
| 52 |
return false; |
| 53 |
} |
| 54 |
|
| 55 |
if (strlen($built) != strlen($signature)) { |
| 56 |
return false; |
| 57 |
} |
| 58 |
|
| 59 |
// Avoid a timing leak with a (hopefully) time insensitive compare |
| 60 |
$result = 0; |
| 61 |
for ($i = 0; $i < strlen($signature); $i ++) { |
| 62 |
$result |= ord($built[$i]) ^ ord($signature[$i]); |
| 63 |
} |
| 64 |
|
| 65 |
return $result == 0; |
| 66 |
} |
| 67 |
} |
| 68 |
|