PluginProbe ʕ •ᴥ•ʔ
Presto Player / trunk
Presto Player vtrunk
4.4.1 4.4.0 4.3.3 4.3.2 4.3.1 4.3.0 4.2.4 4.2.3 4.2.2 4.2.0 4.2.1 trunk 1.10.0 1.10.1 1.10.2 1.11.0 1.12.0 1.13.0 1.14.0 1.14.1 1.5.10 1.5.11 1.5.12 1.5.13 1.5.14 1.5.15 1.5.5 1.5.6 1.5.7 1.5.8 1.5.9 1.6.0 1.6.1 1.6.10 1.6.11 1.6.12 1.6.13 1.6.2 1.6.3 1.6.4 1.6.5 1.6.6 1.6.7 1.6.8 1.6.9 1.7.0 1.7.1 1.7.2 1.8.0 1.8.1 1.8.2 1.8.3 1.8.4 1.8.5 1.8.6 1.9.0 1.9.1 1.9.10 1.9.11 1.9.12 1.9.13 1.9.14 1.9.2 1.9.3 1.9.4 1.9.5 1.9.6 1.9.7 1.9.8 1.9.9 2.0.0 2.0.1 2.0.10 2.0.11 2.0.12 2.0.13 2.0.14 2.0.15 2.0.16 2.0.2 2.0.3 2.0.4 2.0.5 2.0.6 2.0.7 2.0.8 2.0.9 2.1.0 2.2.0 2.2.1 2.2.2 2.2.3 2.2.3-beta1 2.3.0 2.3.1 2.3.2 2.3.3 3.0.0 3.0.0-beta1 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 3.0.6 3.0.7 3.0.8 3.1.0 3.1.1 3.1.2 3.1.3 4.0.0 4.0.1 4.0.2 4.0.3 4.0.4 4.0.5 4.0.6 4.0.7 4.0.8 4.1.0 4.1.1 4.1.2 4.1.3 4.1.4
presto-player / inc / Services / OAuth / PKCE / Verifier.php
presto-player / inc / Services / OAuth / PKCE Last commit date
Verifier.php 1 week ago
Verifier.php
51 lines
1 <?php
2 /**
3 * PKCE S256 verifier.
4 *
5 * @package PrestoPlayer
6 * @subpackage Services\OAuth\PKCE
7 */
8
9 namespace PrestoPlayer\Services\OAuth\PKCE;
10
11 /**
12 * Static helpers for verifying PKCE code challenges (RFC 7636).
13 */
14 class Verifier {
15
16 /**
17 * Verify a code_verifier against a stored S256 challenge.
18 *
19 * Per RFC 7636 §4.6: base64url(sha256(verifier)) == challenge.
20 * Comparison is timing-safe.
21 *
22 * @param string $challenge Stored code_challenge.
23 * @param string $verifier Client-supplied code_verifier.
24 * @return bool True when the verifier matches the challenge.
25 */
26 public static function verifyS256( string $challenge, string $verifier ): bool {
27 if ( '' === $challenge || '' === $verifier ) {
28 return false;
29 }
30
31 if ( ! preg_match( '/^[A-Za-z0-9\-._~]{43,128}$/', $verifier ) ) {
32 return false;
33 }
34
35 $computed = self::base64UrlEncode( hash( 'sha256', $verifier, true ) );
36
37 return hash_equals( $challenge, $computed );
38 }
39
40 /**
41 * Encode bytes as base64url without padding.
42 *
43 * @param string $input Raw binary input.
44 * @return string Base64url-encoded string.
45 */
46 public static function base64UrlEncode( string $input ): string {
47 $base64 = base64_encode( $input ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_encode
48 return rtrim( strtr( $base64, '+/', '-_' ), '=' );
49 }
50 }
51