02f60c7ae6a456a101c8b3cbbef5326596ffbc90
[shpub.git] / src / shpub / Command / Connect.php
1 <?php
2 namespace shpub;
3
4 /**
5  * @link http://micropub.net/draft/
6  * @link http://indieweb.org/authorization-endpoint
7  */
8 class Command_Connect
9 {
10     public static $client_id = 'http://cweiske.de/shpub.htm';
11
12     public function __construct(Config $cfg)
13     {
14         $this->cfg = $cfg;
15     }
16
17     public function run($server, $user, $newKey, $force)
18     {
19         $server = Validator::url($server, 'server');
20         if ($user === null) {
21             //indieweb: homepage is your identity
22             $user = $server;
23         } else {
24             $user = Validator::url($user, 'user');
25         }
26
27         $host = $this->getHost($newKey != '' ? $newKey : $server, $force);
28         if ($host === null) {
29             //already taken
30             return;
31         }
32         if ($host->endpoints->incomplete()) {
33             $host->server = $server;
34             $host->loadEndpoints();
35         }
36
37         list($redirect_uri, $socketStr) = $this->getHttpServerData();
38         $state = time();
39         echo "To authenticate, open the following URL:\n"
40             . $this->getBrowserAuthUrl($host, $user, $redirect_uri, $state)
41             . "\n";
42
43         $authParams = $this->startHttpServer($socketStr);
44         if ($authParams['state'] != $state) {
45             Log::err('Wrong "state" parameter value: ' . $authParams['state']);
46             exit(2);
47         }
48         $code    = $authParams['code'];
49         $userUrl = $authParams['me'];
50         $this->verifyAuthCode($host, $code, $state, $redirect_uri, $userUrl);
51
52         $accessToken = $this->fetchAccessToken(
53             $host, $userUrl, $code, $redirect_uri, $state
54         );
55
56         //all fine. update config
57         $host->user  = $userUrl;
58         $host->token = $accessToken;
59
60         if ($newKey != '') {
61             $hostKey = $newKey;
62         } else {
63             $hostKey = $this->cfg->getHostByName($server);
64             if ($hostKey === null) {
65                 $keyBase = parse_url($host->server, PHP_URL_HOST);
66                 $newKey  = $keyBase;
67                 $count = 0;
68                 while (isset($this->cfg->hosts[$newKey])) {
69                     $newKey = $keyBase . ++$count;
70                 }
71                 $hostKey = $newKey;
72             }
73         }
74         $this->cfg->hosts[$hostKey] = $host;
75         $this->cfg->save();
76         echo "Server configuration $hostKey saved successfully.\n";
77     }
78
79     protected function fetchAccessToken(
80         $host, $userUrl, $code, $redirect_uri, $state
81     ) {
82         $req = new \HTTP_Request2($host->endpoints->token, 'POST');
83         if (version_compare(PHP_VERSION, '5.6.0', '<')) {
84             //correct ssl validation on php 5.5 is a pain, so disable
85             $req->setConfig('ssl_verify_host', false);
86             $req->setConfig('ssl_verify_peer', false);
87         }
88         $req->setHeader('Content-Type: application/x-www-form-urlencoded');
89         $req->setBody(
90             http_build_query(
91                 [
92                     'me'           => $userUrl,
93                     'code'         => $code,
94                     'redirect_uri' => $redirect_uri,
95                     'client_id'    => static::$client_id,
96                     'state'        => $state,
97                 ]
98             )
99         );
100         $res = $req->send();
101         if (intval($res->getStatus() / 100) !== 2) {
102             Log::err('Failed to fetch access token');
103             Log::err('Server responded with HTTP status code ' . $res->getStatus());
104             Log::err($res->getBody());
105             exit(2);
106         }
107         if ($res->getHeader('content-type') != 'application/x-www-form-urlencoded') {
108             Log::err('Wrong content type in auth verification response');
109             exit(2);
110         }
111         parse_str($res->getBody(), $tokenParams);
112         if (!isset($tokenParams['access_token'])) {
113             Log::err('"access_token" missing');
114             exit(2);
115         }
116
117         $accessToken = $tokenParams['access_token'];
118         return $accessToken;
119     }
120
121     protected function getBrowserAuthUrl($host, $user, $redirect_uri, $state)
122     {
123         return $host->endpoints->authorization
124             . '?me=' . urlencode($user)
125             . '&client_id=' . urlencode(static::$client_id)
126             . '&redirect_uri=' . urlencode($redirect_uri)
127             . '&state=' . $state
128             . '&scope=post'
129             . '&response_type=code';
130     }
131
132     protected function getHost($keyOrServer, $force)
133     {
134         $host = new Config_Host();
135         $key = $this->cfg->getHostByName($keyOrServer);
136         if ($key !== null) {
137             $host = $this->cfg->hosts[$key];
138             if (!$force && $host->token != '') {
139                 Log::err('Token already available');
140                 return;
141             }
142         }
143         return $host;
144     }
145
146     protected function getHttpServerData()
147     {
148         $ip   = '127.0.0.1';
149         $port = 12345;
150
151         if (isset($_SERVER['SSH_CONNECTION'])) {
152             $parts = explode(' ', $_SERVER['SSH_CONNECTION']);
153             if (count($parts) >= 3) {
154                 $ip = $parts[2];
155             }
156         }
157         if (strpos($ip, ':') !== false) {
158             //ipv6
159             $ip = '[' . $ip . ']';
160         }
161
162         $redirect_uri = 'http://' . $ip . ':' . $port . '/callback';
163         $socketStr    = 'tcp://' . $ip . ':' . $port;
164         return [$redirect_uri, $socketStr];
165     }
166
167     protected function verifyAuthCode($host, $code, $state, $redirect_uri, $me)
168     {
169         $req = new \HTTP_Request2($host->endpoints->authorization, 'POST');
170         if (version_compare(PHP_VERSION, '5.6.0', '<')) {
171             //correct ssl validation on php 5.5 is a pain, so disable
172             $req->setConfig('ssl_verify_host', false);
173             $req->setConfig('ssl_verify_peer', false);
174         }
175         $req->setHeader('Content-Type: application/x-www-form-urlencoded');
176         $req->setBody(
177             http_build_query(
178                 [
179                     'code'         => $code,
180                     'state'        => $state,
181                     'client_id'    => static::$client_id,
182                     'redirect_uri' => $redirect_uri,
183                 ]
184             )
185         );
186         $res = $req->send();
187         if ($res->getHeader('content-type') != 'application/x-www-form-urlencoded') {
188             Log::err('Wrong content type in auth verification response');
189             exit(2);
190         }
191         parse_str($res->getBody(), $verifiedParams);
192         if (!isset($verifiedParams['me'])
193             || $verifiedParams['me'] !== $me
194         ) {
195             Log::err('Non-matching "me" values');
196             exit(2);
197         }
198     }
199
200     protected function startHttpServer($socketStr)
201     {
202         $responseOk = "HTTP/1.0 200 OK\r\n"
203             . "Content-Type: text/plain\r\n"
204             . "\r\n"
205             . "Ok. You may close this tab and return to the shell.\r\n";
206         $responseErr = "HTTP/1.0 400 Bad Request\r\n"
207             . "Content-Type: text/plain\r\n"
208             . "\r\n"
209             . "Bad Request\r\n";
210
211         //5 minutes should be enough for the user to confirm
212         ini_set('default_socket_timeout', 60 * 5);
213         $server = stream_socket_server($socketStr, $errno, $errstr);
214         if (!$server) {
215             Log::err('Error starting HTTP server');
216             return false;
217         }
218
219         do {
220             $sock = stream_socket_accept($server);
221             if (!$sock) {
222                 Log::err('Error accepting socket connection');
223                 exit(1);
224             }
225
226             $headers = [];
227             $body    = null;
228             $content_length = 0;
229             //read request headers
230             while (false !== ($line = trim(fgets($sock)))) {
231                 if ('' === $line) {
232                     break;
233                 }
234                 $regex = '#^Content-Length:\s*([[:digit:]]+)\s*$#i';
235                 if (preg_match($regex, $line, $matches)) {
236                     $content_length = (int) $matches[1];
237                 }
238                 $headers[] = $line;
239             }
240
241             // read content/body
242             if ($content_length > 0) {
243                 $body = fread($sock, $content_length);
244             }
245
246             // send response
247             list($method, $url, $httpver) = explode(' ', $headers[0]);
248             if ($method == 'GET') {
249                 $parts = parse_url($url);
250                 if (isset($parts['path']) && $parts['path'] == '/callback'
251                     && isset($parts['query'])
252                 ) {
253                     parse_str($parts['query'], $query);
254                     if (isset($query['code'])
255                         && isset($query['state'])
256                         && isset($query['me'])
257                     ) {
258                         fwrite($sock, $responseOk);
259                         fclose($sock);
260                         return $query;
261                     }
262                 }
263             }
264
265             fwrite($sock, $responseErr);
266             fclose($sock);
267         } while (true);
268     }
269 }
270 ?>