Req #59286 [Opn]: Need to be able to support OAuth extensions.
| From: | felipe@php.net | Date: | Wed, 12 Oct 2011 18:17:43 +0000 |
| Subject: | Req #59286 [Opn]: Need to be able to support OAuth extensions. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-164265@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=59286&edit=1
ID: 59286
Updated by: felipe@php.net
Reported by: joe at manvscode dot com
Summary: Need to be able to support OAuth extensions.
Status: Open
Type: Feature/Change Request
Package: oauth
PHP Version: 5.3.2
Block user comment: N
Private report: N
New Comment:
test
Previous Comments:
------------------------------------------------------------------------
[2011-10-05 16:29:43] jawed@php.net
On the consumer side, no. Though I think there should be a way
to do so. The problem is - we'd have to make a distinction
between which parameters are used in the SBS and which are
not.
------------------------------------------------------------------------
[2011-10-05 14:29:09] sites at hubmed dot org
Is there currently a method for adding oauth_body_hash to the OAuth Authorization header, when using
OAUTH_HTTP_METHOD_PUT to upload a file?
------------------------------------------------------------------------
[2010-07-02 00:44:49] jawed@php.net
We had actually discussed that specific extension and its'
implementation. IIRC, the conclusion we reached basically we
can only check that the signature matches per the OAuth Core
spec but generating the actual oauth_body_hash would not be
easy to generalize. There might be some Content-Type checks
too.
FWIW, ideally if the OAuth parameters come in the
Authorization header you can call
OAuthProvider::setRequiredParams("oauth_body_hash") but it
would be up to the implementer to generate and verify the
oauth_body_hash.
- JJ
------------------------------------------------------------------------
[2010-06-29 14:09:50] joe at manvscode dot com
Description:
------------
It isn't clear how extensions can be supported--like this one:
http://oauth.googlecode.com/svn/spec/ext/body_hash/1.0/drafts/3/spec.html
This is needed for providers that are expecting data posted and a content-type other than
"application/x-www-form-urlencoded" (i.e. in the case of XML/JSON posting).
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=59286&edit=1