Doc #67744 [Asn->Csd]: Exclude parameters from signature

From: Date: Thu, 13 Nov 2014 22:03:49 +0000
Subject: Doc #67744 [Asn->Csd]: Exclude parameters from signature
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-11634@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67744&edit=1 ID: 67744 Updated by: cweiske@php.net Reported by: cweiske@php.net Summary: Exclude parameters from signature -Status: Assigned +Status: Closed Type: Documentation Problem Package: oauth Operating System: Debian PHP Version: Irrelevant -Assigned To: datibbaw +Assigned To: cweiske Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2014-11-13 22:02:53] cweiske@php.net Automatic comment from SVN on behalf of cweiske Revision: http://svn.php.net/viewvc/?view=revision&revision=335181 Log: Fix doc bug #67744: Exclude parameters from signature ------------------------------------------------------------------------ [2014-09-21 06:51:58] krakjoe@php.net Assigning to someone with a clue ... ------------------------------------------------------------------------ [2014-08-03 10:48:18] cweiske@php.net I can confirm that setParam("foo", null); works. So it is a problem of missing documentation. ------------------------------------------------------------------------ [2014-08-02 17:43:20] jawed@php.net I think the bug here is the lack of documentation around ignoring parameters. Rasmus had a good example on his blog post @ http://toys.lerdorf.com/archives/55-Writing-an-OAuth-Provider-Service.html Summary: you need to pass NULL as the value to OAuthProvider::setParam (ie, $provider->setParam('name', NULL)). I'll hold off on releasing 1.2.4 in case someone disagrees this is a documentation issue vs implementation. ------------------------------------------------------------------------ [2014-08-02 03:26:38] cweiske@php.net Description: ------------ My webapp uses mod_rewrite to rewrite URLs for easier processing in PHP: > /user/cweiske -> user.php?name=cweiske OAuth clients use http://example.org/user/cweiske as URL and generate the signature for it. OAuthProvider::checkOAuthRequest() uses the same URL because I pass it, but it also uses the GET parameter $_GET[name] during signature verification. Unsetting it via unset($_GET['name']) unfortunately does not work, so I'm left with invalid signatures. I see two solutions: 1. Read the modified $_GET array 2. Add a "ignoreParam" method to OAuthProvider (this is with pecl/oauth 1.2.3) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67744&edit=1

« previous php.doc.bugs (#11634) next »