Doc #67744 [Asn->Csd]: Exclude parameters from signature
| From: | cweiske@php.net | Date: | Thu, 13 Nov 2014 22:03:49 +0000 |
| Subject: | Doc #67744 [Asn->Csd]: Exclude parameters from signature | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-11634@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67744&edit=1
ID: 67744
Updated by: cweiske@php.net
Reported by: cweiske@php.net
Summary: Exclude parameters from signature
-Status: Assigned
+Status: Closed
Type: Documentation Problem
Package: oauth
Operating System: Debian
PHP Version: Irrelevant
-Assigned To: datibbaw
+Assigned To: cweiske
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2014-11-13 22:02:53] cweiske@php.net
Automatic comment from SVN on behalf of cweiske
Revision: http://svn.php.net/viewvc/?view=revision&revision=335181
Log: Fix doc bug #67744: Exclude parameters from signature
------------------------------------------------------------------------
[2014-09-21 06:51:58] krakjoe@php.net
Assigning to someone with a clue ...
------------------------------------------------------------------------
[2014-08-03 10:48:18] cweiske@php.net
I can confirm that setParam("foo", null); works.
So it is a problem of missing documentation.
------------------------------------------------------------------------
[2014-08-02 17:43:20] jawed@php.net
I think the bug here is the lack of documentation around ignoring parameters. Rasmus had a good
example on his blog post @ http://toys.lerdorf.com/archives/55-Writing-an-OAuth-Provider-Service.html
Summary: you need to pass NULL as the value to OAuthProvider::setParam (ie,
$provider->setParam('name', NULL)).
I'll hold off on releasing 1.2.4 in case someone disagrees this is a documentation issue vs
implementation.
------------------------------------------------------------------------
[2014-08-02 03:26:38] cweiske@php.net
Description:
------------
My webapp uses mod_rewrite to rewrite URLs for easier processing in PHP:
> /user/cweiske -> user.php?name=cweiske
OAuth clients use http://example.org/user/cweiske as
URL and generate the signature for it.
OAuthProvider::checkOAuthRequest() uses the same URL because I pass it, but it also uses the GET
parameter $_GET[name] during signature verification.
Unsetting it via unset($_GET['name']) unfortunately does not work, so I'm left with
invalid signatures.
I see two solutions:
1. Read the modified $_GET array
2. Add a "ignoreParam" method to OAuthProvider
(this is with pecl/oauth 1.2.3)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67744&edit=1