← All changes
|
vendor/payplug/payplug-php/lib/Payplug/Authentication.php
+321
-11
1.0.5
→
3.1.0
View file →
| @@ -1,10 +1,14 @@ | ||
| 1 | 1 | <?php |
| 2 | + | |
| 2 | 3 | namespace Payplug; |
| 3 | 4 | |
| 5 | +use Exception; | |
| 6 | +use Payplug\Exception\ConfigurationException; | |
| 7 | + | |
| 4 | 8 | /** |
| 5 | - * | |
| 6 | - */ | |
| 9 | + * The Authentication DAO simplifies the access to most useful customer methods | |
| 10 | + **/ | |
| 7 | 11 | class Authentication |
| 8 | 12 | { |
| 9 | 13 | /** |
| 10 | 14 | * Retrieve existing API keys for an user, using his email and password. |
| @@ -10,10 +14,10 @@ | ||
| 10 | 14 | * Retrieve existing API keys for an user, using his email and password. |
| 11 | 15 | * This function is for user-friendly interface purpose only. |
| 12 | 16 | * You should probably not use this more than once, login/password MUST NOT be stored and API Keys are enough to interact with API. |
| 13 | 17 | * |
| 14 | - * @param string $email the user email | |
| 15 | - * @param string $password the user password | |
| 18 | + * @param string $email the user email | |
| 19 | + * @param string $password the user password | |
| 16 | 20 | * |
| 17 | 21 | * @return null|array the API keys |
| 18 | 22 | * |
| 19 | 23 | * @throws Exception\BadRequestException |
| @@ -31,19 +35,21 @@ | ||
| 31 | 35 | |
| 32 | 36 | /** |
| 33 | 37 | * Retrieve account info. |
| 34 | 38 | * |
| 35 | - * @param Payplug $payplug the client configuration | |
| 39 | + * @param Payplug $payplug the client configuration | |
| 36 | 40 | * |
| 37 | 41 | * @return null|array the account settings |
| 38 | 42 | * |
| 39 | 43 | * @throws Exception\ConfigurationNotSetException |
| 44 | + * @throws ConfigurationException | |
| 40 | 45 | */ |
| 41 | - public static function getAccount(Payplug $payplug = null) | |
| 46 | + public static function getAccount($payplug = null) | |
| 42 | 47 | { |
| 43 | 48 | if ($payplug === null) { |
| 44 | 49 | $payplug = Payplug::getDefaultConfiguration(); |
| 45 | 50 | } |
| 51 | + self::validateToken($payplug); | |
| 46 | 52 | |
| 47 | 53 | $httpClient = new Core\HttpClient($payplug); |
| 48 | 54 | $response = $httpClient->get(Core\APIRoutes::getRoute(Core\APIRoutes::ACCOUNT_RESOURCE)); |
| 49 | 55 | |
| @@ -52,20 +58,23 @@ | ||
| 52 | 58 | |
| 53 | 59 | /** |
| 54 | 60 | * Retrieve the account permissions |
| 55 | 61 | * |
| 56 | - * @param Payplug $payplug the client configuration | |
| 62 | + * @param Payplug $payplug the client configuration | |
| 57 | 63 | * |
| 58 | 64 | * @return null|array the account permissions |
| 59 | 65 | * |
| 60 | 66 | * @throws Exception\ConfigurationNotSetException |
| 67 | + * @throws ConfigurationException | |
| 61 | 68 | */ |
| 62 | - public static function getPermissions(Payplug $payplug = null) | |
| 69 | + public static function getPermissions($payplug = null) | |
| 63 | 70 | { |
| 64 | 71 | if ($payplug === null) { |
| 65 | 72 | $payplug = Payplug::getDefaultConfiguration(); |
| 66 | 73 | } |
| 67 | 74 | |
| 75 | + self::validateToken($payplug); | |
| 76 | + | |
| 68 | 77 | $httpClient = new Core\HttpClient($payplug); |
| 69 | 78 | $response = $httpClient->get(Core\APIRoutes::getRoute(Core\APIRoutes::ACCOUNT_RESOURCE)); |
| 70 | 79 | |
| 71 | 80 | return $response['httpResponse']['permissions']; |
| @@ -75,21 +84,322 @@ | ||
| 75 | 84 | * Retrieve the account permissions, using email and password. |
| 76 | 85 | * This function is for user-friendly interface purpose only. |
| 77 | 86 | * You should probably not use this more than once, login/password MUST NOT be stored and API Keys are enough to interact with API. |
| 78 | 87 | * |
| 79 | - * @param string $email the user email | |
| 80 | - * @param string $password the user password | |
| 88 | + * @param string $email the user email | |
| 89 | + * @param string $password the user password | |
| 81 | 90 | * |
| 82 | 91 | * @return null|array the account permissions |
| 83 | 92 | * |
| 84 | 93 | * @throws Exception\ConfigurationNotSetException |
| 94 | + * @throws ConfigurationException | |
| 85 | 95 | */ |
| 86 | 96 | public static function getPermissionsByLogin($email, $password) |
| 87 | 97 | { |
| 88 | 98 | $keys = self::getKeysByLogin($email, $password); |
| 89 | - $payplug = Payplug::setSecretKey($keys['httpResponse']['secret_keys']['live']); | |
| 99 | + $payplug = Payplug::init(array( | |
| 100 | + 'secretKey' => $keys['httpResponse']['secret_keys']['live'], | |
| 101 | + 'apiVersion' => null, | |
| 102 | + )); | |
| 103 | + self::validateToken($payplug); | |
| 104 | + | |
| 90 | 105 | $httpClient = new Core\HttpClient($payplug); |
| 91 | 106 | $response = $httpClient->get(Core\APIRoutes::getRoute(Core\APIRoutes::ACCOUNT_RESOURCE)); |
| 92 | 107 | |
| 93 | 108 | return $response['httpResponse']['permissions']; |
| 109 | + } | |
| 110 | + | |
| 111 | + /** | |
| 112 | + * Retrieve publisable keys | |
| 113 | + * | |
| 114 | + * @param Payplug $payplug the client configuration | |
| 115 | + * | |
| 116 | + * @return array|false | |
| 117 | + *createClientIdAndSecret | |
| 118 | + * @throws Exception | |
| 119 | + */ | |
| 120 | + public static function getPublishableKeys($payplug = null) | |
| 121 | + { | |
| 122 | + if ($payplug === null) { | |
| 123 | + $payplug = Payplug::getDefaultConfiguration(); | |
| 124 | + } | |
| 125 | + $httpClient = new Core\HttpClient($payplug); | |
| 126 | + try { | |
| 127 | + $response = $httpClient->post(Core\APIRoutes::getRoute(Core\APIRoutes::PUBLISHABLE_KEYS)); | |
| 128 | + return $response; | |
| 129 | + } catch (Exception $e) { | |
| 130 | + return false; | |
| 131 | + } | |
| 132 | + } | |
| 133 | + | |
| 134 | + /** | |
| 135 | + * Generate a token JWT from a given client id and secret | |
| 136 | + * | |
| 137 | + * @param string $client_id | |
| 138 | + * @param string $client_secret | |
| 139 | + * | |
| 140 | + * @return array | |
| 141 | + */ | |
| 142 | + public static function generateJWT($client_id = '', $client_secret = '') | |
| 143 | + { | |
| 144 | + if ($client_id == '') { | |
| 145 | + return array(); | |
| 146 | + } | |
| 147 | + if ($client_secret == '') { | |
| 148 | + return array(); | |
| 149 | + } | |
| 150 | + | |
| 151 | + $httpClient = new Core\HttpClient(null); | |
| 152 | + try { | |
| 153 | + $route = Core\APIRoutes::getRoute(Core\APIRoutes::OAUTH2_TOKEN_RESOURCE, null, array(), array(), false); | |
| 154 | + $response = $httpClient->post( | |
| 155 | + $route, | |
| 156 | + array( | |
| 157 | + 'grant_type' => 'client_credentials', | |
| 158 | + 'audience' => 'https://www.payplug.com', | |
| 159 | + ), false, null, array( | |
| 160 | + 'Content-Type: application/x-www-form-urlencoded', | |
| 161 | + 'Authorization: Basic ' . base64_encode($client_id . ':' . $client_secret) | |
| 162 | + ), | |
| 163 | + 'x-www-form-urlencoded'); | |
| 164 | + | |
| 165 | + if (!isset($response['httpResponse']) || empty($response['httpResponse'])) { | |
| 166 | + return array(); | |
| 167 | + } | |
| 168 | + | |
| 169 | + $response['httpResponse']['expires_date'] = time() + $response['httpResponse']['expires_in'] - 30; | |
| 170 | + | |
| 171 | + return $response; | |
| 172 | + } catch (Exception $e) { | |
| 173 | + return array(); | |
| 174 | + } | |
| 175 | + } | |
| 176 | + | |
| 177 | + /** | |
| 178 | + * Generate a token JWT OneShot. | |
| 179 | + * | |
| 180 | + * @param string $authorization_code | |
| 181 | + * @param string $callback_uri | |
| 182 | + * @param string $client_id | |
| 183 | + * @param string $code_verifier | |
| 184 | + * | |
| 185 | + * @return array the token JWT OneShot | |
| 186 | + * | |
| 187 | + * @throws Exception | |
| 188 | + */ | |
| 189 | + public static function generateJWTOneShot($authorization_code='', $callback_uri='', $client_id = '', $code_verifier = '') | |
| 190 | + { | |
| 191 | + if ($authorization_code == '') { | |
| 192 | + return array(); | |
| 193 | + } | |
| 194 | + | |
| 195 | + if ($callback_uri == '') { | |
| 196 | + return array(); | |
| 197 | + } | |
| 198 | + | |
| 199 | + if ($client_id == '') { | |
| 200 | + return array(); | |
| 201 | + } | |
| 202 | + | |
| 203 | + if ($code_verifier == '') { | |
| 204 | + return array(); | |
| 205 | + } | |
| 206 | + | |
| 207 | + $httpClient = new Core\HttpClient(null); | |
| 208 | + try { | |
| 209 | + $route = Core\APIRoutes::getRoute(Core\APIRoutes::OAUTH2_TOKEN_RESOURCE, null, array(), array(), false); | |
| 210 | + $response = $httpClient->post( | |
| 211 | + $route, | |
| 212 | + array( | |
| 213 | + 'grant_type' => 'authorization_code', | |
| 214 | + 'code' => $authorization_code, | |
| 215 | + 'redirect_uri' => $callback_uri, | |
| 216 | + 'client_id' => $client_id, | |
| 217 | + 'code_verifier' => $code_verifier | |
| 218 | + ), | |
| 219 | + false, | |
| 220 | + null, | |
| 221 | + array( | |
| 222 | + 'Accept: application/json', | |
| 223 | + 'Content-Type: application/x-www-form-urlencoded' | |
| 224 | + ), | |
| 225 | + 'application/x-www-form-urlencoded' | |
| 226 | + ); | |
| 227 | + } catch (Exception $e) { | |
| 228 | + $response = array(); | |
| 229 | + } | |
| 230 | + | |
| 231 | + return $response; | |
| 232 | + } | |
| 233 | + | |
| 234 | + /** | |
| 235 | + * Validates the Payplug token | |
| 236 | + * | |
| 237 | + * @param Payplug $payplug | |
| 238 | + * @return void | |
| 239 | + * @throws ConfigurationException | |
| 240 | + */ | |
| 241 | + private static function validateToken($payplug) | |
| 242 | + { | |
| 243 | + $token = $payplug->getToken(); | |
| 244 | + if (empty($token)) { | |
| 245 | + throw new ConfigurationException('The Payplug configuration requires a valid token.'); | |
| 246 | + } | |
| 247 | + } | |
| 248 | + | |
| 249 | + /** | |
| 250 | + * Create a client ID and secret for a given mode | |
| 251 | + * | |
| 252 | + * @param $company_id | |
| 253 | + * @param $client_name | |
| 254 | + * @param $mode | |
| 255 | + * @param $session | |
| 256 | + * @param Payplug|null $payplug | |
| 257 | + * | |
| 258 | + * @return array | |
| 259 | + * @throws ConfigurationException | |
| 260 | + * @throws Exception\ConfigurationNotSetException | |
| 261 | + * @throws Exception\ConnectionException | |
| 262 | + * @throws Exception\HttpException | |
| 263 | + * @throws Exception\UnexpectedAPIResponseException | |
| 264 | + */ | |
| 265 | + public static function createClientIdAndSecret($company_id = '', $client_name = '', $mode = '', $session = null, $payplug = null) | |
| 266 | + { | |
| 267 | + if ($payplug === null) { | |
| 268 | + $payplug = Payplug::getDefaultConfiguration(); | |
| 269 | + } | |
| 270 | + | |
| 271 | + $httpClient = new Core\HttpClient($payplug); | |
| 272 | + $response = array(); | |
| 273 | + $route = Core\APIRoutes::getServiceRoute(Core\APIRoutes::CLIENT_RESOURCE); | |
| 274 | + try { | |
| 275 | + $response = $httpClient->post( | |
| 276 | + $route, | |
| 277 | + array( | |
| 278 | + 'company_id' => $company_id, | |
| 279 | + 'client_name' => $client_name, | |
| 280 | + 'client_type' => 'client_credentials_flow', | |
| 281 | + 'mode' => $mode, | |
| 282 | + )); | |
| 283 | + } catch (Exception $e) { | |
| 284 | + return $response; | |
| 285 | + } | |
| 286 | + | |
| 287 | + return $response; | |
| 288 | + } | |
| 289 | + | |
| 290 | + /** | |
| 291 | + * Get the return url to register user through the portal | |
| 292 | + * | |
| 293 | + * @param string $setup_redirection_uri | |
| 294 | + * @param string $oauth_callback_uri | |
| 295 | + * | |
| 296 | + * @return array | |
| 297 | + * @throws Exception\ConnectionException | |
| 298 | + * @throws Exception\HttpException | |
| 299 | + * @throws Exception\UnexpectedAPIResponseException | |
| 300 | + */ | |
| 301 | + public static function getRegisterUrl($setup_redirection_uri = '', $oauth_callback_uri = '') | |
| 302 | + { | |
| 303 | + if (empty($setup_redirection_uri)) { | |
| 304 | + throw new Exception\ConfigurationException('Expected string values for setup redirection uri.'); | |
| 305 | + } | |
| 306 | + if (empty($oauth_callback_uri)) { | |
| 307 | + throw new Exception\ConfigurationException('Expected string values for oauth callback uri.'); | |
| 308 | + } | |
| 309 | + | |
| 310 | + $url_datas = array( | |
| 311 | + 'setup_redirection_uri' => $setup_redirection_uri, | |
| 312 | + 'oauth_callback_uri' => $oauth_callback_uri, | |
| 313 | + ); | |
| 314 | + | |
| 315 | + $route = Core\APIRoutes::getServiceRoute(Core\APIRoutes::PLUGIN_SETUP_SERVICE, $url_datas); | |
| 316 | + | |
| 317 | + return $route; | |
| 318 | + } | |
| 319 | + | |
| 320 | + /** | |
| 321 | + * Redirect to callback page and provide an authorization_code | |
| 322 | + * | |
| 323 | + * @param $client_id | |
| 324 | + * @param $redirect_uri | |
| 325 | + * @param $code_verifier | |
| 326 | + * @param Payplug|null $payplug | |
| 327 | + * @throws ConfigurationException | |
| 328 | + * @throws Exception\ConfigurationNotSetException | |
| 329 | + * @throws Exception\ConnectionException | |
| 330 | + * @throws Exception\HttpException | |
| 331 | + * @throws Exception\UnexpectedAPIResponseException | |
| 332 | + */ | |
| 333 | + public static function initiateOAuth($client_id='', $redirect_uri='', $code_verifier='') | |
| 334 | + { | |
| 335 | + $hash = hash("sha256", $code_verifier); | |
| 336 | + $code_challenge = base64_encode(pack("H*", $hash)); | |
| 337 | + $code_challenge = strtr($code_challenge, "+/", "-_"); | |
| 338 | + $code_challenge = rtrim($code_challenge, "="); | |
| 339 | + | |
| 340 | + $portal_url_datas = array( | |
| 341 | + 'client_id' => $client_id, | |
| 342 | + 'redirect_uri' => $redirect_uri, | |
| 343 | + 'response_type' => 'code', | |
| 344 | + 'state' => bin2hex(openssl_random_pseudo_bytes(10)), | |
| 345 | + 'scope' => 'openid offline profile email', | |
| 346 | + 'audience' => 'https://www.payplug.com', | |
| 347 | + 'code_challenge' => $code_challenge, | |
| 348 | + 'code_challenge_method' => 'S256', | |
| 349 | + ); | |
| 350 | + | |
| 351 | + $portal_url = Core\APIRoutes::getRoute(Core\APIRoutes::OAUTH2_AUTH_RESOURCE, null, array(), $portal_url_datas, false); | |
| 352 | + | |
| 353 | + header("Location: $portal_url"); | |
| 354 | + } | |
| 355 | + | |
| 356 | + /** | |
| 357 | + * Check if given token is expired and if so, regenerate a new one | |
| 358 | + * | |
| 359 | + * @param array $client_data | |
| 360 | + * @param array $token | |
| 361 | + * | |
| 362 | + * @return array | |
| 363 | + */ | |
| 364 | + public static function validateJWT($client_data = array(), $token = array()) | |
| 365 | + { | |
| 366 | + if (!is_array($client_data) || empty($client_data)) { | |
| 367 | + return array( | |
| 368 | + 'result' => false, | |
| 369 | + 'token' => null, | |
| 370 | + 'need_update' => false, | |
| 371 | + ); | |
| 372 | + } | |
| 373 | + if (!is_array($token) || empty($token)) { | |
| 374 | + return array( | |
| 375 | + 'result' => false, | |
| 376 | + 'token' => null, | |
| 377 | + 'need_update' => false, | |
| 378 | + ); | |
| 379 | + } | |
| 380 | + | |
| 381 | + $current_date = time(); | |
| 382 | + if ($token['expires_date'] > $current_date) { | |
| 383 | + return array( | |
| 384 | + 'result' => true, | |
| 385 | + 'token' => $token, | |
| 386 | + 'need_update' => false, | |
| 387 | + ); | |
| 388 | + } | |
| 389 | + | |
| 390 | + $token = self::generateJWT($client_data['client_id'], $client_data['client_secret']); | |
| 391 | + if (empty($token) || !isset($token['httpResponse'])) { | |
| 392 | + return array( | |
| 393 | + 'result' => false, | |
| 394 | + 'token' => null, | |
| 395 | + 'need_update' => false, | |
| 396 | + ); | |
| 397 | + } | |
| 398 | + | |
| 399 | + return array( | |
| 400 | + 'result' => true, | |
| 401 | + 'token' => $token['httpResponse'], | |
| 402 | + 'need_update' => true, | |
| 403 | + ); | |
| 94 | 404 | } |
| 95 | 405 | } |