← All changes
|
includes/sdk/google/google/auth/src/AccessToken.php
+43
-43
1.2.5
→
1.4.2
View file →
| @@ -14,30 +14,30 @@ | ||
| 14 | 14 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 15 | 15 | * See the License for the specific language governing permissions and |
| 16 | 16 | * limitations under the License. |
| 17 | 17 | */ |
| 18 | -namespace Dudlewebs\WPMCS\Google\Auth; | |
| 18 | +namespace Dudlewebs\WPMCS\GCP\Google\Auth; | |
| 19 | 19 | |
| 20 | 20 | use DateTime; |
| 21 | -use Dudlewebs\WPMCS\Firebase\JWT\ExpiredException; | |
| 22 | -use Dudlewebs\WPMCS\Firebase\JWT\JWT; | |
| 23 | -use Dudlewebs\WPMCS\Firebase\JWT\Key; | |
| 24 | -use Dudlewebs\WPMCS\Firebase\JWT\SignatureInvalidException; | |
| 25 | -use Dudlewebs\WPMCS\Google\Auth\Cache\MemoryCacheItemPool; | |
| 26 | -use Dudlewebs\WPMCS\Google\Auth\HttpHandler\HttpClientCache; | |
| 27 | -use Dudlewebs\WPMCS\Google\Auth\HttpHandler\HttpHandlerFactory; | |
| 28 | -use Dudlewebs\WPMCS\GuzzleHttp\Psr7\Request; | |
| 29 | -use Dudlewebs\WPMCS\GuzzleHttp\Psr7\Utils; | |
| 21 | +use Dudlewebs\WPMCS\GCP\Firebase\JWT\ExpiredException; | |
| 22 | +use Dudlewebs\WPMCS\GCP\Firebase\JWT\JWT; | |
| 23 | +use Dudlewebs\WPMCS\GCP\Firebase\JWT\Key; | |
| 24 | +use Dudlewebs\WPMCS\GCP\Firebase\JWT\SignatureInvalidException; | |
| 25 | +use Dudlewebs\WPMCS\GCP\Google\Auth\Cache\MemoryCacheItemPool; | |
| 26 | +use Dudlewebs\WPMCS\GCP\Google\Auth\HttpHandler\HttpClientCache; | |
| 27 | +use Dudlewebs\WPMCS\GCP\Google\Auth\HttpHandler\HttpHandlerFactory; | |
| 28 | +use Dudlewebs\WPMCS\GCP\GuzzleHttp\Psr7\Request; | |
| 29 | +use Dudlewebs\WPMCS\GCP\GuzzleHttp\Psr7\Utils; | |
| 30 | 30 | use InvalidArgumentException; |
| 31 | -use Dudlewebs\WPMCS\phpseclib3\Crypt\PublicKeyLoader; | |
| 32 | -use Dudlewebs\WPMCS\phpseclib3\Crypt\RSA; | |
| 33 | -use Dudlewebs\WPMCS\phpseclib3\Math\BigInteger; | |
| 34 | -use Dudlewebs\WPMCS\Psr\Cache\CacheItemPoolInterface; | |
| 31 | +use Dudlewebs\WPMCS\GCP\phpseclib3\Crypt\PublicKeyLoader; | |
| 32 | +use Dudlewebs\WPMCS\GCP\phpseclib3\Crypt\RSA; | |
| 33 | +use Dudlewebs\WPMCS\GCP\phpseclib3\Math\BigInteger; | |
| 34 | +use Dudlewebs\WPMCS\GCP\Psr\Cache\CacheItemPoolInterface; | |
| 35 | 35 | use RuntimeException; |
| 36 | -use Dudlewebs\WPMCS\SimpleJWT\InvalidTokenException; | |
| 37 | -use Dudlewebs\WPMCS\SimpleJWT\JWT as SimpleJWT; | |
| 38 | -use Dudlewebs\WPMCS\SimpleJWT\Keys\KeyFactory; | |
| 39 | -use Dudlewebs\WPMCS\SimpleJWT\Keys\KeySet; | |
| 36 | +use Dudlewebs\WPMCS\GCP\SimpleJWT\InvalidTokenException; | |
| 37 | +use Dudlewebs\WPMCS\GCP\SimpleJWT\JWT as SimpleJWT; | |
| 38 | +use Dudlewebs\WPMCS\GCP\SimpleJWT\Keys\KeyFactory; | |
| 39 | +use Dudlewebs\WPMCS\GCP\SimpleJWT\Keys\KeySet; | |
| 40 | 40 | use TypeError; |
| 41 | 41 | use UnexpectedValueException; |
| 42 | 42 | /** |
| 43 | 43 | * Wrapper around Google Access Tokens which provides convenience functions. |
| @@ -60,12 +60,12 @@ | ||
| 60 | 60 | * @var CacheItemPoolInterface |
| 61 | 61 | */ |
| 62 | 62 | private $cache; |
| 63 | 63 | /** |
| 64 | - * @param callable $httpHandler [optional] An HTTP Handler to deliver PSR-7 requests. | |
| 65 | - * @param CacheItemPoolInterface $cache [optional] A PSR-6 compatible cache implementation. | |
| 64 | + * @param callable|null $httpHandler [optional] An HTTP Handler to deliver PSR-7 requests. | |
| 65 | + * @param CacheItemPoolInterface|null $cache [optional] A PSR-6 compatible cache implementation. | |
| 66 | 66 | */ |
| 67 | - public function __construct(callable $httpHandler = null, CacheItemPoolInterface $cache = null) | |
| 67 | + public function __construct(?callable $httpHandler = null, ?CacheItemPoolInterface $cache = null) | |
| 68 | 68 | { |
| 69 | 69 | $this->httpHandler = $httpHandler ?: HttpHandlerFactory::build(HttpClientCache::getHttpClient()); |
| 70 | 70 | $this->cache = $cache ?: new MemoryCacheItemPool(); |
| 71 | 71 | } |
| @@ -109,9 +109,9 @@ | ||
| 109 | 109 | // for backwards compatibility |
| 110 | 110 | // Check signature against each available cert. |
| 111 | 111 | $certs = $this->getCerts($certsLocation, $cacheKey, $options); |
| 112 | 112 | $alg = $this->determineAlg($certs); |
| 113 | - if (!in_array($alg, ['RS256', 'ES256'])) { | |
| 113 | + if (!\in_array($alg, ['RS256', 'ES256'])) { | |
| 114 | 114 | throw new InvalidArgumentException('unrecognized "alg" in certs, expected ES256 or RS256'); |
| 115 | 115 | } |
| 116 | 116 | try { |
| 117 | 117 | if ($alg == 'RS256') { |
| @@ -216,9 +216,9 @@ | ||
| 216 | 216 | $keys[$cert['kid']] = new Key($publicKey, 'RS256'); |
| 217 | 217 | } |
| 218 | 218 | $payload = $this->callJwtStatic('decode', [$token, $keys]); |
| 219 | 219 | if ($audience) { |
| 220 | - if (!property_exists($payload, 'aud') || $payload->aud != $audience) { | |
| 220 | + if (!\property_exists($payload, 'aud') || $payload->aud != $audience) { | |
| 221 | 221 | throw new UnexpectedValueException('Audience does not match'); |
| 222 | 222 | } |
| 223 | 223 | } |
| 224 | 224 | // support HTTP and HTTPS issuers |
| @@ -223,9 +223,9 @@ | ||
| 223 | 223 | } |
| 224 | 224 | // support HTTP and HTTPS issuers |
| 225 | 225 | // @see https://developers.google.com/identity/sign-in/web/backend-auth |
| 226 | 226 | $issuers = $issuer ? [$issuer] : [self::OAUTH2_ISSUER, self::OAUTH2_ISSUER_HTTPS]; |
| 227 | - if (!isset($payload->iss) || !in_array($payload->iss, $issuers)) { | |
| 227 | + if (!isset($payload->iss) || !\in_array($payload->iss, $issuers)) { | |
| 228 | 228 | throw new UnexpectedValueException('Issuer does not match'); |
| 229 | 229 | } |
| 230 | 230 | return (array) $payload; |
| 231 | 231 | } |
| @@ -238,9 +238,9 @@ | ||
| 238 | 238 | * @return bool Returns True if the revocation was successful, otherwise False. |
| 239 | 239 | */ |
| 240 | 240 | public function revoke($token, array $options = []) |
| 241 | 241 | { |
| 242 | - if (is_array($token)) { | |
| 242 | + if (\is_array($token)) { | |
| 243 | 243 | if (isset($token['refresh_token'])) { |
| 244 | 244 | $token = $token['refresh_token']; |
| 245 | 245 | } else { |
| 246 | 246 | $token = $token['access_token']; |
| @@ -245,9 +245,9 @@ | ||
| 245 | 245 | } else { |
| 246 | 246 | $token = $token['access_token']; |
| 247 | 247 | } |
| 248 | 248 | } |
| 249 | - $body = Utils::streamFor(http_build_query(['token' => $token])); | |
| 249 | + $body = Utils::streamFor(\http_build_query(['token' => $token])); | |
| 250 | 250 | $request = new Request('POST', self::OAUTH2_REVOKE_URI, ['Cache-Control' => 'no-store', 'Content-Type' => 'application/x-www-form-urlencoded'], $body); |
| 251 | 251 | $httpHandler = $this->httpHandler; |
| 252 | 252 | $response = $httpHandler($request, $options); |
| 253 | 253 | return $response->getStatusCode() == 200; |
| @@ -298,28 +298,28 @@ | ||
| 298 | 298 | private function retrieveCertsFromLocation($url, array $options = []) |
| 299 | 299 | { |
| 300 | 300 | // If we're retrieving a local file, just grab it. |
| 301 | 301 | $expireTime = '+1 hour'; |
| 302 | - if (strpos($url, 'http') !== 0) { | |
| 303 | - if (!file_exists($url)) { | |
| 304 | - throw new InvalidArgumentException(sprintf('Failed to retrieve verification certificates from path: %s.', $url)); | |
| 302 | + if (\strpos($url, 'http') !== 0) { | |
| 303 | + if (!\file_exists($url)) { | |
| 304 | + throw new InvalidArgumentException(\sprintf('Failed to retrieve verification certificates from path: %s.', $url)); | |
| 305 | 305 | } |
| 306 | - return [json_decode((string) file_get_contents($url), \true), $expireTime]; | |
| 306 | + return [\json_decode((string) \file_get_contents($url), \true), $expireTime]; | |
| 307 | 307 | } |
| 308 | 308 | $httpHandler = $this->httpHandler; |
| 309 | 309 | $response = $httpHandler(new Request('GET', $url), $options); |
| 310 | 310 | if ($response->getStatusCode() == 200) { |
| 311 | 311 | if ($cacheControl = $response->getHeaderLine('Cache-Control')) { |
| 312 | - array_map(function ($value) use (&$expireTime) { | |
| 313 | - list($key, $value) = explode('=', $value) + [null, null]; | |
| 314 | - if (trim($key) == 'max-age') { | |
| 312 | + \array_map(function ($value) use(&$expireTime) { | |
| 313 | + list($key, $value) = \explode('=', $value) + [null, null]; | |
| 314 | + if (\trim($key) == 'max-age') { | |
| 315 | 315 | $expireTime = '+' . $value . ' seconds'; |
| 316 | 316 | } |
| 317 | - }, explode(',', $cacheControl)); | |
| 317 | + }, \explode(',', $cacheControl)); | |
| 318 | 318 | } |
| 319 | - return [json_decode((string) $response->getBody(), \true), $expireTime]; | |
| 319 | + return [\json_decode((string) $response->getBody(), \true), $expireTime]; | |
| 320 | 320 | } |
| 321 | - throw new RuntimeException(sprintf('Failed to retrieve verification certificates: "%s".', $response->getBody()->getContents()), $response->getStatusCode()); | |
| 321 | + throw new RuntimeException(\sprintf('Failed to retrieve verification certificates: "%s".', $response->getBody()->getContents()), $response->getStatusCode()); | |
| 322 | 322 | } |
| 323 | 323 | /** |
| 324 | 324 | * @return void |
| 325 | 325 | */ |
| @@ -324,9 +324,9 @@ | ||
| 324 | 324 | * @return void |
| 325 | 325 | */ |
| 326 | 326 | private function checkAndInitializePhpsec() |
| 327 | 327 | { |
| 328 | - if (!class_exists(RSA::class)) { | |
| 328 | + if (!\class_exists(RSA::class)) { | |
| 329 | 329 | throw new RuntimeException('Please require phpseclib/phpseclib v3 to use this utility.'); |
| 330 | 330 | } |
| 331 | 331 | } |
| 332 | 332 | /** |
| @@ -332,13 +332,13 @@ | ||
| 332 | 332 | /** |
| 333 | 333 | * @return string |
| 334 | 334 | * @throws TypeError If the key cannot be initialized to a string. |
| 335 | 335 | */ |
| 336 | - private function loadPhpsecPublicKey(string $modulus, string $exponent): string | |
| 336 | + private function loadPhpsecPublicKey(string $modulus, string $exponent) : string | |
| 337 | 337 | { |
| 338 | 338 | $key = PublicKeyLoader::load(['n' => new BigInteger($this->callJwtStatic('urlsafeB64Decode', [$modulus]), 256), 'e' => new BigInteger($this->callJwtStatic('urlsafeB64Decode', [$exponent]), 256)]); |
| 339 | 339 | $formattedPublicKey = $key->toString('PKCS8'); |
| 340 | - if (!is_string($formattedPublicKey)) { | |
| 340 | + if (!\is_string($formattedPublicKey)) { | |
| 341 | 341 | throw new TypeError('Failed to initialize the key'); |
| 342 | 342 | } |
| 343 | 343 | return $formattedPublicKey; |
| 344 | 344 | } |
| @@ -347,9 +347,9 @@ | ||
| 347 | 347 | */ |
| 348 | 348 | private function checkSimpleJwt() |
| 349 | 349 | { |
| 350 | 350 | // @codeCoverageIgnoreStart |
| 351 | - if (!class_exists(SimpleJwt::class)) { | |
| 351 | + if (!\class_exists(SimpleJwt::class)) { | |
| 352 | 352 | throw new RuntimeException('Please require kelvinmo/simplejwt ^0.2 to use this utility.'); |
| 353 | 353 | } |
| 354 | 354 | // @codeCoverageIgnoreEnd |
| 355 | 355 | } |
| @@ -361,9 +361,9 @@ | ||
| 361 | 361 | * @return mixed |
| 362 | 362 | */ |
| 363 | 363 | protected function callJwtStatic($method, array $args = []) |
| 364 | 364 | { |
| 365 | - return call_user_func_array([JWT::class, $method], $args); | |
| 365 | + return \call_user_func_array([JWT::class, $method], $args); | |
| 366 | 366 | // @phpstan-ignore-line |
| 367 | 367 | } |
| 368 | 368 | /** |
| 369 | 369 | * Provide a hook to mock calls to the JWT static methods. |
| @@ -372,9 +372,9 @@ | ||
| 372 | 372 | * @return mixed |
| 373 | 373 | */ |
| 374 | 374 | protected function callSimpleJwtDecode(array $args = []) |
| 375 | 375 | { |
| 376 | - return call_user_func_array([SimpleJwt::class, 'decode'], $args); | |
| 376 | + return \call_user_func_array([SimpleJwt::class, 'decode'], $args); | |
| 377 | 377 | } |
| 378 | 378 | /** |
| 379 | 379 | * Generate a cache key based on the cert location using sha1 with the |
| 380 | 380 | * exception of using "federated_signon_certs_v3" to preserve BC. |
| @@ -383,8 +383,8 @@ | ||
| 383 | 383 | * @return string |
| 384 | 384 | */ |
| 385 | 385 | private function getCacheKeyFromCertLocation($certsLocation) |
| 386 | 386 | { |
| 387 | - $key = $certsLocation === self::FEDERATED_SIGNON_CERT_URL ? 'federated_signon_certs_v3' : sha1($certsLocation); | |
| 387 | + $key = $certsLocation === self::FEDERATED_SIGNON_CERT_URL ? 'federated_signon_certs_v3' : \sha1($certsLocation); | |
| 388 | 388 | return 'google_auth_certs_cache|' . $key; |
| 389 | 389 | } |
| 390 | 390 | } |