oauth2-server/resource-server-securing-api.md

47 lines
1.3 KiB
Markdown
Raw Normal View History

2014-09-30 22:44:18 +01:00
---
layout: default
title: Securing your API
permalink: /resource-server/securing-your-api/
---
# Securing your API
2016-03-24 15:45:40 +00:00
This library provides a PSR-7 friendly resource server middleware that can validate access tokens.
2014-09-30 22:44:18 +01:00
2016-03-24 15:45:40 +00:00
## Setup
2014-09-30 22:44:18 +01:00
2016-03-24 15:45:40 +00:00
Wherever you intialize your objects, initialize a new instance of the resource server with the storage interfaces:
2018-01-29 10:25:35 +01:00
~~~ php
2016-03-24 15:45:40 +00:00
// Init our repositories
2016-04-17 13:16:40 +01:00
$accessTokenRepository = new AccessTokenRepository(); // instance of AccessTokenRepositoryInterface
2016-03-24 15:45:40 +00:00
2016-04-17 13:16:40 +01:00
// Path to authorization server's public key
$publicKeyPath = 'file://path/to/public.key';
2016-03-24 15:45:40 +00:00
// Setup the authorization server
2016-04-17 13:16:40 +01:00
$server = new \League\OAuth2\Server\ResourceServer(
2016-03-24 15:45:40 +00:00
$accessTokenRepository,
$publicKeyPath
2014-09-30 22:44:18 +01:00
);
2018-01-29 10:25:35 +01:00
~~~
2014-09-30 22:44:18 +01:00
2016-03-24 15:45:40 +00:00
Then add the middleware to your stack:
2014-09-30 22:44:18 +01:00
2018-01-29 10:25:35 +01:00
~~~ php
2016-03-24 15:45:40 +00:00
new \League\OAuth2\Server\Middleware\ResourceServerMiddleware($server);
2018-01-29 10:25:35 +01:00
~~~
2014-09-30 22:44:18 +01:00
2016-03-24 15:45:40 +00:00
## Implementation
2014-09-30 22:44:18 +01:00
2016-03-24 15:45:40 +00:00
The authorization header on an incoming request will automatically be validated.
2014-09-30 22:44:18 +01:00
2016-03-24 15:45:40 +00:00
If the access token is valid the following attributes will be set on the ServerRequest:
2014-09-30 22:44:18 +01:00
2016-03-24 15:45:40 +00:00
* `oauth_access_token_id` - the access token identifier
* `oauth_client_id` - the client identifier
* `oauth_user_id` - the user identifier represented by the access token
* `oauth_scopes` - an array of string scope identifiers
2014-09-30 22:44:18 +01:00
If the authorization is invalid an instance of `OAuthServerException::accessDenied` will be thrown.