Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions lib/Event/InternalTokenRequestedEvent.php
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,8 @@ class InternalTokenRequestedEvent extends Event {

public function __construct(
private string $targetAudience,
private array $extraScopes = [],
private string $resource = '',
) {
parent::__construct();
}
Expand All @@ -32,6 +34,14 @@ public function setTargetAudience(string $targetAudience): void {
$this->targetAudience = $targetAudience;
}

public function getExtraScopes(): array {
return $this->extraScopes;
}

public function getResource(): string {
return $this->resource;
}

public function getToken(): ?Token {
return $this->token;
}
Expand Down
4 changes: 3 additions & 1 deletion lib/Listener/InternalTokenRequestedListener.php
Original file line number Diff line number Diff line change
Expand Up @@ -37,12 +37,14 @@ public function handle(Event $event): void {
}

$targetAudience = $event->getTargetAudience();
$extraScopes = $event->getExtraScopes();
$resource = $event->getResource();
$this->logger->debug('[InternalTokenRequestedListener] received request for audience: ' . $targetAudience);

// generate a token pair with the Oidc provider app
$userId = $this->userSession->getUser()?->getUID();
if ($userId !== null) {
$ncProviderToken = $this->tokenService->getTokenFromOidcProviderApp($userId, $targetAudience);
$ncProviderToken = $this->tokenService->getTokenFromOidcProviderApp($userId, $targetAudience, $extraScopes, $resource);
if ($ncProviderToken !== null) {
$event->setToken($ncProviderToken);
}
Expand Down
5 changes: 3 additions & 2 deletions lib/Service/TokenService.php
Original file line number Diff line number Diff line change
Expand Up @@ -321,7 +321,7 @@ public function getExchangedToken(string $targetAudience): Token {
* @param string $targetAudience
* @return Token|null
*/
public function getTokenFromOidcProviderApp(string $userId, string $targetAudience): ?Token {
public function getTokenFromOidcProviderApp(string $userId, string $targetAudience, array $extraScopes = [], string $resource = ''): ?Token {
if (!class_exists(\OCA\OIDCIdentityProvider\AppInfo\Application::class)) {
$this->logger->warning('[TokenService] Failed to get token from Oidc provider app, oidc app is not installed');
return null;
Expand All @@ -336,7 +336,8 @@ public function getTokenFromOidcProviderApp(string $userId, string $targetAudien
}

try {
$generationEvent = new \OCA\OIDCIdentityProvider\Event\TokenGenerationRequestEvent($targetAudience, $userId);
$scope = implode(' ', $extraScopes);
$generationEvent = new \OCA\OIDCIdentityProvider\Event\TokenGenerationRequestEvent($targetAudience, $userId, $scope, $resource);
$this->eventDispatcher->dispatchTyped($generationEvent);
if ($generationEvent->getAccessToken() === null || $generationEvent->getIdToken() === null) {
$this->logger->debug('[TokenService] The Oidc provider app did not generate any access/id token');
Expand Down
Loading