Oauth2Controller
extends BcAdminAppController
in package
Admin OAuth2 Controller
OAuth2認証エンドポイントを提供(認証が必要なエンドポイントのみ)
Table of Contents
Constants
- SESSION_AUTH_REQUESTS : mixed = 'BcMcp.authRequests'
- 認可リクエストを保持するセッションキー
- MAX_PENDING_AUTH_REQUESTS : mixed = 5
- セッションに保持する認可リクエストの最大件数
Properties
- $Authentication : AuthenticationComponent
- $BcMessage : BcMessageComponent
- $_View : View
- View
- $oauth2ConfigError : OAuth2ConfigurationException|null
- OAuth2 の設定不備
- $oauth2Service : OAuth2Service|null
- OAuth2サービス
Methods
- __construct() : void|ResponseInterface
- AppController constructor.
- _blackHoleCallback() : void
- Securityコンポーネントのブラックホールからのコールバック
- ajaxError() : void
- Ajax用のエラーを出力する
- authorize() : Response|ResponseInterface
- 認可エンドポイント
- beforeFilter() : void
- リクエスト処理前に設定不備を確認する
- beforeRender() : Response|void|null
- Before Render
- dispatchLayerEvent() : bool|Event
- イベントを発火
- getService() : array<string|int, mixed>|mixed|object
- Get Service
- hasService() : bool
- Has Service
- initialize() : void
- 初期化
- notFound() : void
- NOT FOUNDページを出力する
- options() : Response
- OPTIONSリクエスト対応
- redirectIfIsNotSameSite() : Response|void|null
- siteUrlや、cmsUrlと現在のURLが違う場合には、そちらのURLにリダイレクトを行う setting.php にて、cmsUrlとして、cmsUrlを定義した場合にはそちらを優先する
- redirectIfIsRequireMaintenance() : Response|void|null
- メンテナンス画面へのリダイレクトが必要な場合にリダイレクトする
- requirePermission() : bool
- パーミッションが必要かどうかを確認する
- setTitle() : void
- Set Title
- setupFrontView() : void
- フロント用のViewクラスをセットアップする
- _checkReferer() : bool
- リファラチェックを行う
- loadViewConditions() : void
- 画面の情報をセッションから読み込む
- restrictNonPublicAccess() : void
- 未認証ユーザーによる非公開データへのアクセスを制限する
- saveDblog() : EntityInterface
- データベースログを記録する
- saveViewConditions() : void
- 画面の情報をセッションに保存する
- setAdminTheme() : void
- 管理画面用テーマをセットする
- setHelp() : void
- Set Help
- setSearch() : void
- Set Search
- setViewConditions() : void
- 画面の情報をセットする
- completeAuthorization() : Response|ResponseInterface
- 認可を完了させる
Constants
SESSION_AUTH_REQUESTS
認可リクエストを保持するセッションキー
public
mixed
SESSION_AUTH_REQUESTS
= 'BcMcp.authRequests'
同時に開かれた複数の同意画面(別タブでの GET など)を区別できるよう、 単一の値ではなく consent_id => AuthorizationRequest のマップとして保持する。 これにより「タブ1で開いた同意画面のまま、セッション上の認可リクエストだけが 別クライアントのものにすり替わる」経路を防ぐ。
MAX_PENDING_AUTH_REQUESTS
セッションに保持する認可リクエストの最大件数
private
mixed
MAX_PENDING_AUTH_REQUESTS
= 5
同意画面を開いたまま放置される(GET だけして POST しない)ケースが 積み重なってもセッションが際限なく肥大化しないよう、上限を超えた 分は古いものから破棄する。
Properties
$Authentication
public
AuthenticationComponent
$Authentication
$BcMessage
public
BcMessageComponent
$BcMessage
$_View
View
protected
View
$_View
$oauth2ConfigError
OAuth2 の設定不備
private
OAuth2ConfigurationException|null
$oauth2ConfigError
= null
$oauth2Service
OAuth2サービス
private
OAuth2Service|null
$oauth2Service
= null
Methods
__construct()
AppController constructor.
public
__construct([ServerRequest|null $request = null ][, Response|null $response = null ][, string|null $name = null ][, EventManagerInterface|null $eventManager = null ][, ComponentRegistry|null $components = null ]) : void|ResponseInterface
Parameters
- $request : ServerRequest|null = null
- $response : Response|null = null
- $name : string|null = null
- $eventManager : EventManagerInterface|null = null
- $components : ComponentRegistry|null = null
Tags
Return values
void|ResponseInterface_blackHoleCallback()
Securityコンポーネントのブラックホールからのコールバック
public
_blackHoleCallback(string $err, mixed $exception) : void
フォーム改ざん対策・CSRF対策・SSL制限・HTTPメソッド制限などへの違反が原因で Securityコンポーネントに"ブラックホールされた"場合の動作を指定する
Parameters
- $err : string
-
エラーの種類
- $exception : mixed
Tags
ajaxError()
Ajax用のエラーを出力する
public
ajaxError([int $errorNo = 500 ][, mixed $message = '' ]) : void
since 5.0.5 このメソッドは非推奨です。
Parameters
- $errorNo : int = 500
-
エラーのステータスコード
- $message : mixed = ''
-
エラーメッセージ
Tags
authorize()
認可エンドポイント
public
authorize() : Response|ResponseInterface
Authorization Code Grant の開始点。GET で認可リクエストを検証して セッションへ保持し、同意画面にはセッションの内容だけを表示する。 baserCMS の管理画面認証が必要。
Return values
Response|ResponseInterfacebeforeFilter()
リクエスト処理前に設定不備を確認する
public
beforeFilter(EventInterface $event) : void
Parameters
- $event : EventInterface
-
イベント
beforeRender()
Before Render
public
beforeRender(EventInterface $event) : Response|void|null
Parameters
- $event : EventInterface
Tags
Return values
Response|void|nulldispatchLayerEvent()
イベントを発火
public
dispatchLayerEvent(string $name[, array<string|int, mixed> $data = [] ][, mixed $options = [] ]) : bool|Event
Parameters
- $name : string
- $data : array<string|int, mixed> = []
- $options : mixed = []
Tags
Return values
bool|EventgetService()
Get Service
public
getService(mixed $service) : array<string|int, mixed>|mixed|object
Parameters
- $service : mixed
Tags
Return values
array<string|int, mixed>|mixed|objecthasService()
Has Service
public
hasService(mixed $service) : bool
Parameters
- $service : mixed
Tags
Return values
boolinitialize()
初期化
public
initialize() : void
notFound()
NOT FOUNDページを出力する
public
notFound() : void
Tags
options()
OPTIONSリクエスト対応
public
options() : Response
Return values
ResponseredirectIfIsNotSameSite()
siteUrlや、cmsUrlと現在のURLが違う場合には、そちらのURLにリダイレクトを行う setting.php にて、cmsUrlとして、cmsUrlを定義した場合にはそちらを優先する
public
redirectIfIsNotSameSite() : Response|void|null
Tags
Return values
Response|void|nullredirectIfIsRequireMaintenance()
メンテナンス画面へのリダイレクトが必要な場合にリダイレクトする
public
redirectIfIsRequireMaintenance() : Response|void|null
Tags
Return values
Response|void|nullrequirePermission()
パーミッションが必要かどうかを確認する
public
requirePermission(ServerRequest $request) : bool
デフォルトは true であるが、設定ファイルで明示的に false に 設定されている場合は false となる。
Parameters
- $request : ServerRequest
Return values
boolsetTitle()
Set Title
public
setTitle(string $title) : void
Parameters
- $title : string
Tags
setupFrontView()
フロント用のViewクラスをセットアップする
public
setupFrontView() : void
Tags
_checkReferer()
リファラチェックを行う
protected
_checkReferer() : bool
Tags
Return values
boolloadViewConditions()
画面の情報をセッションから読み込む
protected
loadViewConditions([array<string|int, mixed> $targetModel = [] ][, array<string|int, mixed>|string $options = [] ]) : void
初期値が設定されている場合は初期値を設定した上で、セッションで上書きし、 ServerRequestに設定する。
Parameters
- $targetModel : array<string|int, mixed> = []
- $options : array<string|int, mixed>|string = []
-
オプション
default: 読み出す初期値(初期値:[])group: 保存するグループ名(初期値:'')post: POSTデータを保存するかどうか(初期値:true)get: GETデータを保存するかどうか(初期値:false)
Tags
restrictNonPublicAccess()
未認証ユーザーによる非公開データへのアクセスを制限する
protected
restrictNonPublicAccess() : void
未認証ユーザーが preview / status を利用して非公開データを閲覧することを防ぐ。 デフォルト(フロント・管理画面)では、未認証時にこれらのパラメータを除去し、 公開データのみに強制する。認証済み(正規のプレビュー機能を含む)はそのまま許可する。 API では BcApiController でオーバーライドし、preview を拒否(Forbidden)する。
Tags
saveDblog()
データベースログを記録する
protected
saveDblog(string $message) : EntityInterface
Parameters
- $message : string
Tags
Return values
EntityInterfacesaveViewConditions()
画面の情報をセッションに保存する
protected
saveViewConditions([array<string|int, mixed> $targetModel = [] ][, array<string|int, mixed> $options = [] ]) : void
次のセッション名に保存。
- POSTデータ: BcApp.viewConditions.{$contentsName}.data.{$model}
- クエリパラメーター: BcApp.viewConditions.{$contentsName}.query
$contentsNameは次の形式となる。 {$controllerName}{$actionName}.{$group}
ただし、ページネーションにおいて、1ページ目はクエリパラメーターpage を付けない仕様となっているため
page は保存しない。
Parameters
- $targetModel : array<string|int, mixed> = []
- $options : array<string|int, mixed> = []
-
オプション
group: 保存するグループ名(初期値:'')post: POSTデータを保存するかどうか(初期値:true)get: GETデータを保存するかどうか(初期値:false)
Tags
setAdminTheme()
管理画面用テーマをセットする
protected
setAdminTheme() : void
優先順位 BcSiteConfig::get('admin_theme') > Configure::read('BcApp.adminTheme')
Tags
setHelp()
Set Help
protected
setHelp(string $template) : void
Parameters
- $template : string
Tags
setSearch()
Set Search
protected
setSearch(string $template) : void
Parameters
- $template : string
Tags
setViewConditions()
画面の情報をセットする
protected
setViewConditions([array<string|int, mixed> $targetModel = [] ][, array<string|int, mixed> $options = [] ]) : void
POSTデータとクエリパラメーターをセッションに保存した上で、 指定されたデフォルト値も含めて ServerRequest に設定する。
$this->setViewConditions(['Content'], [
'group' => 'index',
'default' => [
'query' => ['limit' => 10],
'data' => ['title' => 'default']
],
'get' => true
]);
Parameters
- $targetModel : array<string|int, mixed> = []
-
ターゲットとなるモデル
- $options : array<string|int, mixed> = []
-
オプション
default: 読み出す初期値(初期値:[])group: 保存するグループ名(初期値:'')post: POSTデータを保存するかどうか(初期値:true)get: GETデータを保存するかどうか(初期値:false)
Tags
completeAuthorization()
認可を完了させる
private
completeAuthorization() : Response|ResponseInterface
クエリもボディも認可の内容としては読まず、GET 時に検証してセッションへ 保持した認可リクエストのみを使う。ボディから読むのは、どの同意画面の ものかを指す consent_id のみで、スコープやリダイレクト先といった認可の 内容は一切含まれない。これにより同意画面で見せた権限と、実際に 発行される権限がすり替わる余地を無くす。