Merge pull request #573 from ismailbaskin/master

Include redirect_uri check on authorization endpoint
This commit is contained in:
Andrew Millington
2017-11-19 20:57:27 +00:00
committed by GitHub
3 changed files with 55 additions and 0 deletions

View File

@ -240,6 +240,11 @@ class AuthCodeGrant extends AbstractAuthorizeGrant
$this->getEmitter()->emit(new RequestEvent(RequestEvent::CLIENT_AUTHENTICATION_FAILED, $request));
throw OAuthServerException::invalidClient();
}
} elseif (is_array($client->getRedirectUri()) && count($client->getRedirectUri()) !== 1
|| empty($client->getRedirectUri())
) {
$this->getEmitter()->emit(new RequestEvent(RequestEvent::CLIENT_AUTHENTICATION_FAILED, $request));
throw OAuthServerException::invalidClient();
}
$scopes = $this->validateScopes(