}
if ($application['redirect_uri'] != 'urn:ietf:wg:oauth:2.0:oob') {
- DI::app()->redirect($application['redirect_uri'] . (strpos($application['redirect_uri'], '?') ? '&' : '?') . http_build_query(['code' => $token['code'], 'state' => $request['state']]));
+ DI::app()->redirect($request['redirect_uri'] . (strpos($request['redirect_uri'], '?') ? '&' : '?') . http_build_query(['code' => $token['code'], 'state' => $request['state']]));
}
self::$oauth_code = $token['code'];
use Friendica\Module\Special\HTTPException;
use Friendica\Security\OAuth;
use Friendica\Util\DateTimeFormat;
+use GuzzleHttp\Psr7\Uri;
use Psr\Http\Message\ResponseInterface;
/**
$me = null;
} elseif ($request['grant_type'] == 'authorization_code') {
// For security reasons only allow freshly created tokens
- $condition = ["`redirect_uri` = ? AND `id` = ? AND `code` = ? AND `created_at` > ?",
- $request['redirect_uri'], $application['id'], $request['code'], DateTimeFormat::utc('now - 5 minutes')];
+ $uri = new Uri($request['redirect_uri']);
+ $condition = ["`redirect_uri` LIKE ? AND `id` = ? AND `code` = ? AND `created_at` > ?",
+ '%' . $uri->getScheme() . '://' . $uri->getHost() . $uri->getPath() . '%', $application['id'], $request['code'], DateTimeFormat::utc('now - 5 minutes')];
$token = DBA::selectFirst('application-view', ['access_token', 'created_at', 'uid'], $condition);
if (!DBA::isResult($token)) {
use Friendica\Model\User;
use Friendica\Module\BaseApi;
use Friendica\Util\DateTimeFormat;
+use GuzzleHttp\Psr7\Uri;
/**
* OAuth Server
if (!empty($client_secret)) {
$condition['client_secret'] = $client_secret;
}
+
if (!empty($redirect_uri)) {
- $condition['redirect_uri'] = $redirect_uri;
+ $uri = new Uri($redirect_uri);
+ $redirect_uri = $uri->getScheme() . '://' . $uri->getHost() . $uri->getPath();
+ $condition = DBA::mergeConditions($condition, ["`redirect_uri` LIKE ?", '%' . $redirect_uri . '%']);
}
$application = DBA::selectFirst('application', [], $condition);
Logger::warning('Application not found', $condition);
return [];
}
+
+ // The redirect_uri could contain several URI that are separated by spaces.
+ if (($application['redirect_uri'] != $redirect_uri) && !in_array($redirect_uri, explode(' ', $application['redirect_uri']))) {
+ return [];
+ }
+
return $application;
}