annotate default/assets/vendors/theme-widgets/vendor/abraham/twitteroauth/src/SignatureMethod.php @ 0:1d038bc9b3d2 default tip

Up:default
author Liny <dev@neowd.com>
date Sat, 31 May 2025 09:21:51 +0800
parents
children
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
0
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
1 <?php
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
2 /**
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
3 * The MIT License
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
4 * Copyright (c) 2007 Andy Smith
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
5 */
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
6 namespace Abraham\TwitterOAuth;
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
7
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
8 /**
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
9 * A class for implementing a Signature Method
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
10 * See section 9 ("Signing Requests") in the spec
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
11 */
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
12 abstract class SignatureMethod
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
13 {
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
14 /**
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
15 * Needs to return the name of the Signature Method (ie HMAC-SHA1)
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
16 *
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
17 * @return string
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
18 */
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
19 abstract public function getName();
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
20
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
21 /**
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
22 * Build up the signature
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
23 * NOTE: The output of this function MUST NOT be urlencoded.
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
24 * the encoding is handled in OAuthRequest when the final
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
25 * request is serialized
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
26 *
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
27 * @param Request $request
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
28 * @param Consumer $consumer
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
29 * @param Token $token
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
30 *
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
31 * @return string
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
32 */
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
33 abstract public function buildSignature(Request $request, Consumer $consumer, Token $token = null);
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
34
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
35 /**
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
36 * Verifies that a given signature is correct
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
37 *
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
38 * @param Request $request
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
39 * @param Consumer $consumer
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
40 * @param Token $token
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
41 * @param string $signature
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
42 *
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
43 * @return bool
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
44 */
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
45 public function checkSignature(Request $request, Consumer $consumer, Token $token, $signature)
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
46 {
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
47 $built = $this->buildSignature($request, $consumer, $token);
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
48
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
49 // Check for zero length, although unlikely here
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
50 if (strlen($built) == 0 || strlen($signature) == 0) {
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
51 return false;
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
52 }
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
53
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
54 if (strlen($built) != strlen($signature)) {
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
55 return false;
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
56 }
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
57
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
58 // Avoid a timing leak with a (hopefully) time insensitive compare
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
59 $result = 0;
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
60 for ($i = 0; $i < strlen($signature); $i++) {
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
61 $result |= ord($built{$i}) ^ ord($signature{$i});
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
62 }
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
63
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
64 return $result == 0;
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
65 }
1d038bc9b3d2 Up:default
Liny <dev@neowd.com>
parents:
diff changeset
66 }