|
30 | 30 | $scope = "signature aow_manage"; |
31 | 31 | endif; |
32 | 32 |
|
| 33 | +function generateCodeVerifier() { |
| 34 | + return bin2hex(random_bytes(32)); |
| 35 | +} |
| 36 | + |
| 37 | +function generateCodeChallenge($code_verifier) { |
| 38 | + return rtrim(strtr(base64_encode(hash('sha256', $code_verifier, true)), '+/', '-_'), '='); |
| 39 | +} |
| 40 | + |
| 41 | +$use_pkce = true; |
| 42 | +$code_verifier = generateCodeVerifier(); |
| 43 | +$code_challenge = generateCodeChallenge($code_verifier); |
| 44 | + |
| 45 | +$_SESSION['code_verifier'] = $code_verifier; |
| 46 | + |
33 | 47 | $authorizationURL = $authorizationEndpoint . 'auth?' . http_build_query( |
34 | 48 | [ |
35 | 49 | 'redirect_uri' => $redirectURI, |
36 | 50 | 'scope' => $scope, |
37 | 51 | 'client_id' => $clientID, |
38 | 52 | 'state' => $state, |
39 | | - 'response_type' => 'code' |
| 53 | + 'response_type' => 'code', |
| 54 | + 'code_challenge' => $code_challenge, |
| 55 | + 'code_challenge_method' => 'S256' |
40 | 56 | ] |
41 | 57 | ); |
42 | 58 |
|
|
64 | 80 | $authorizationEndpoint . 'token', [ |
65 | 81 | 'grant_type' => 'authorization_code', |
66 | 82 | 'redirect_uri' => $redirectURI, |
67 | | - 'code' => $code |
| 83 | + 'code' => $code, |
| 84 | + 'code_verifier' => $code_verifier |
68 | 85 | ], [ |
69 | 86 | 'Authorization: Basic ' . base64_encode($clientID . ':' .$clientSecret), |
70 | 87 | ], true |
71 | 88 | ); |
72 | 89 |
|
73 | 90 | if (!isset($response->access_token)) { |
74 | 91 | echo "\nError fetching access token\n"; |
| 92 | + $use_pkce = false; |
| 93 | + echo "\nPKCE failed\n"; |
75 | 94 | exit(2); |
76 | 95 | } |
77 | 96 |
|
| 97 | +if (!$use_pkce) { |
| 98 | + // Start Authorization Code Grant flow without PKCE |
| 99 | + $authorizationURL = $authorizationEndpoint . 'auth?' . http_build_query([ |
| 100 | + 'redirect_uri' => $redirectURI, |
| 101 | + 'scope' => $scope, |
| 102 | + 'client_id' => $clientID, |
| 103 | + 'state' => $state, |
| 104 | + 'response_type' => 'code' |
| 105 | + ]);} |
| 106 | + |
| 107 | +if (!$use_pkce){ |
| 108 | + $code = $auth['code']; |
| 109 | + echo "\nGetting an access token...\n"; |
| 110 | + |
| 111 | + $response = http( |
| 112 | + $authorizationEndpoint . 'token', [ |
| 113 | + 'grant_type' => 'authorization_code', |
| 114 | + 'redirect_uri' => $redirectURI, |
| 115 | + 'code' => $code |
| 116 | + ], [ |
| 117 | + 'Authorization: Basic ' . base64_encode($clientID . ':' .$clientSecret), |
| 118 | + ], true |
| 119 | + ); |
| 120 | + |
| 121 | +} |
| 122 | + |
78 | 123 | $accessToken = $response->access_token; |
79 | 124 | file_put_contents($outputFile, $accessToken); |
80 | 125 | echo "\nAccess token has been written to " . $outputFile . "\n\n"; |
|
0 commit comments