Subversion Repositories oidplus

Rev

Rev 570 | Rev 576 | Go to most recent revision | Blame | Compare with Previous | Last modification | View Log | RSS feed

  1. <?php
  2.  
  3. /*
  4.  * OIDplus 2.0
  5.  * Copyright 2019 - 2021 Daniel Marschall, ViaThinkSoft
  6.  *
  7.  * Licensed under the Apache License, Version 2.0 (the "License");
  8.  * you may not use this file except in compliance with the License.
  9.  * You may obtain a copy of the License at
  10.  *
  11.  *     http://www.apache.org/licenses/LICENSE-2.0
  12.  *
  13.  * Unless required by applicable law or agreed to in writing, software
  14.  * distributed under the License is distributed on an "AS IS" BASIS,
  15.  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  16.  * See the License for the specific language governing permissions and
  17.  * limitations under the License.
  18.  */
  19.  
  20. if (!defined('INSIDE_OIDPLUS')) die();
  21.  
  22. class OIDplusAuthContentStoreJWT extends OIDplusAuthContentStoreDummy {
  23.  
  24.         // Individual functions
  25.  
  26.         public function loadJWT($jwt) {
  27.                 \Firebase\JWT\JWT::$leeway = 60; // leeway in seconds
  28.                 if (OIDplus::getPkiStatus()) {
  29.                         $pubKey = OIDplus::config()->getValue('oidplus_public_key');
  30.                         $this->content = (array) \Firebase\JWT\JWT::decode($jwt, $pubKey, array('RS256', 'RS384', 'RS512'));
  31.                 } else {
  32.                         $key = OIDplus::baseConfig()->getValue('SERVER_SECRET', '');
  33.                         $key = hash_pbkdf2('sha512', $key, '', 10000, 64/*256bit*/, false);
  34.                         $this->content = (array) \Firebase\JWT\JWT::decode($jwt, $key, array('HS256', 'HS384', 'HS512'));
  35.                 }
  36.         }
  37.  
  38.         public function getJWTToken($lifetime=100*365*24*60*60) {
  39.                 $payload = $this->content;
  40.                 $payload["iss"] = "http://oidplus.com";
  41.                 $payload["aud"] = "http://oidplus.com";
  42.                 $payload["jti"] = gen_uuid();
  43.                 $payload["iat"] = time();
  44.                 $payload["exp"] = time() + $lifetime;
  45.  
  46.                 if (OIDplus::getPkiStatus()) {
  47.                         $privKey = OIDplus::config()->getValue('oidplus_private_key');
  48.                         return \Firebase\JWT\JWT::encode($payload, $privKey, 'RS512');
  49.                 } else {
  50.                         $key = OIDplus::baseConfig()->getValue('SERVER_SECRET', '');
  51.                         $key = hash_pbkdf2('sha512', $key, '', 10000, 64/*256bit*/, false);
  52.                         return \Firebase\JWT\JWT::encode($payload, $key, 'HS512');
  53.                 }
  54.         }
  55.  
  56. }
  57.