public function oidc_logout() { $open_id_url = 'https://noshchartingsystem.com/openid-connect-server-webapp/'; $practice = DB::table('practiceinfo')->where('practice_id', '=', '1')->first(); $client_id = $practice->uma_client_id; $client_secret = $practice->uma_client_secret; $url = route('oidc_logout'); $oidc = new OpenIDConnectClient($open_id_url, $client_id, $client_secret); $oidc->setRedirectURL($url); $oidc->setAccessToken(Session::get('oidc_auth_access_token')); $oidc->revoke(); Session::forget('oidc_auth_access_token'); return Redirect::intended('logout'); }
protected function uma_api_build($command, $url, $send_object = null, $put_delete = null) { //$open_id_url = 'http://162.243.111.18/uma-server-webapp/'; $open_id_url = str_replace('/nosh', '/uma-server-webapp/', URL::to('/')); $practice = DB::table('practiceinfo')->where('practice_id', '=', '1')->first(); $client_id = $practice->uma_client_id; $client_secret = $practice->uma_client_secret; //$api_endpoint = 'http://162.243.111.18/uma-server-webapp/api/' . $command; $api_endpoint = str_replace('/nosh', '/uma-server-webapp/api/' . $command, URL::to('/')); $oidc = new OpenIDConnectClient($open_id_url, $client_id, $client_secret); $oidc->setRedirectURL($url); $oidc->setAccessToken(Session::get('uma_auth_access_token')); $response = $oidc->api($command, $api_endpoint, $send_object, $put_delete); return $response; }
protected function uma_resource_set($url, $name = null, $icon = null, $scopes = null) { $open_id_url = str_replace('/nosh', '/uma-server-webapp/', URL::to('/')); $practice = DB::table('practiceinfo')->where('practice_id', '=', '1')->first(); $client_id = $practice->uma_client_id; $client_secret = $practice->uma_client_secret; $oidc = new OpenIDConnectClient($open_id_url, $client_id, $client_secret); $oidc->setRedirectURL($url); if (Session::has('uma_auth_pat')) { $oidc->setAccessToken(Session::get('uma_auth_pat')); } else { $oidc->authenticate(true, 'pat'); Session::put('uma_auth_pat', $oidc->getAccessToken()); } $response = $oidc->resource_set($name, $icon, $scopes); return $response; }
function do_login_oidc() { global $DB, $userdata, $username, $ip; if (AUTH_METHOD != "PHP_SESSIONS") { error("You can only use OpenID Connect if the site is using PHP Sessions for authentication."); } if (dbconfig_get('allow_openid_auth', false) == false) { error("OpenID authentication disabled by administrator."); } if (empty(BASEURL)) { error("OpenID authentication requires that 'BASEURL' be configured."); } $provider = dbconfig_get('openid_provider', ''); $clientID = dbconfig_get('openid_clientid', ''); $clientSecret = dbconfig_get('openid_clientsecret', ''); if (empty($provider) || empty($clientID) || empty($clientSecret)) { error("OpenID details are not configured."); } $oidc = new OpenIDConnectClient($provider, $clientID, $clientSecret); $oidc->addScope(array("openid", "email")); // TODO: how to dynamically figure this out properly on all/most servers $oidc->setRedirectURL(BASEURL . "/auth/oid_cb.php"); // For google, forces asking the user what account they want to use every time. $oidc->addAuthParam(array("prompt" => "select_account")); if (isset($_REQUEST["code"])) { // authenticate the code we've received $oidc->authenticate(); } else { // save destination url in session so we can redirect after log in $_SESSION['redirect_after_login'] = $_SERVER['PHP_SELF']; // Launch the OpenID Connect process $oidc->authenticate(); } // we are logged in now, get a bunch of user information from the OID Provider $username = "******" . $oidc->requestUserInfo("sub"); $email = $oidc->requestUserInfo("email"); // Create the user if they don't exist $user = $DB->q('MAYBETUPLE SELECT * FROM user WHERE username = %s', $username); if (!$user) { $u = array(); // Create a team for the user as well if (dbconfig_get("openid_autocreate_team", true)) { $i = array(); $i['name'] = $email; $i['categoryid'] = 2; // Self-registered category id $i['enabled'] = 1; $i['comments'] = "Registered via OIDC by {$ip} on " . date('r'); $teamid = $DB->q("RETURNID INSERT INTO team SET %S", $i); auditlog('team', $teamid, 'registered via OIDC by ' . $ip); $u['teamid'] = $teamid; } $u['username'] = $username; $u['email'] = $email; $u['name'] = $email; $u['password'] = NULL; $newid = $DB->q("RETURNID INSERT INTO user SET %S", $u); auditlog('user', $newid, 'registered via OIDC', $ip); // Assign the team role if we created a team for them if (isset($u['teamid'])) { $DB->q("INSERT INTO `userrole` (`userid`, `roleid`) VALUES ({$newid}, 3)"); } } // Load the information about the user $userdata = $DB->q('MAYBETUPLE SELECT * FROM user WHERE username = %s AND enabled = 1', $username); // Save the username in the session so they are logged in session_start(); $_SESSION['username'] = $username; auditlog('user', $userdata['userid'], 'logged in', $ip); // Update the user's last login time $DB->q('UPDATE user SET last_login = %s, last_ip_address = %s WHERE username = %s', now(), $ip, $username); }