aboutsummaryrefslogtreecommitdiff
path: root/lib/classes/OAuth2/Bridge/AuthCodeRepository.php
blob: 5676622269e9fc60bd5555d2b780d41d0d74646d (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
<?php

namespace Studip\OAuth2\Bridge;

use League\OAuth2\Server\Entities\AuthCodeEntityInterface;
use League\OAuth2\Server\Exception\UniqueTokenIdentifierConstraintViolationException;
use League\OAuth2\Server\Repositories\AuthCodeRepositoryInterface;
use Studip\OAuth2\Models\AuthCode;

class AuthCodeRepository implements AuthCodeRepositoryInterface
{
    use ScopesHelper;

    /**
     * Creates a new AuthCode.
     */
    public function getNewAuthCode(): AuthCodeEntityInterface
    {
        return new AuthCodeEntity();
    }

    /**
     * Persists a new auth code to permanent storage.
     *
     * @return void
     *
     * @throws UniqueTokenIdentifierConstraintViolationException
     */
    public function persistNewAuthCode(AuthCodeEntityInterface $authCodeEntity)
    {
        AuthCode::create([
            'id'         => $authCodeEntity->getIdentifier(),
            'user_id'    => $authCodeEntity->getUserIdentifier(),
            'client_id'  => $authCodeEntity->getClient()->getIdentifier(),
            'scopes'     => $this->formatScopes($authCodeEntity->getScopes()),
            'revoked'    => 0,
            'expires_at' => $authCodeEntity->getExpiryDateTime()->getTimestamp(),
        ]);

        // TODO: Logging and metrics
    }

    /**
     * Revoke an auth code.
     *
     * @param string $codeId
     */
    public function revokeAuthCode($codeId): void
    {
        $authCode = AuthCode::find($codeId);
        if ($authCode) {
            $authCode->revoke();
        }
    }

    /**
     * Check if the auth code has been revoked.
     *
     * @param string $codeId
     *
     * @return bool Return true if this code has been revoked
     */
    public function isAuthCodeRevoked($codeId): bool
    {
        $authCode = AuthCode::find($codeId);

        return $authCode ? $authCode->isRevoked() : true;
    }
}