authorize.php 2.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566
  1. <?php
  2. require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/prerequisites.inc.php';
  3. if (!isset($_SESSION['mailcow_cc_role'])) {
  4. $_SESSION['oauth2_request'] = $_SERVER['REQUEST_URI'];
  5. header('Location: /?oauth');
  6. }
  7. $request = OAuth2\Request::createFromGlobals();
  8. $response = new OAuth2\Response();
  9. if (!$oauth2_server->validateAuthorizeRequest($request, $response)) {
  10. $response->send();
  11. exit();
  12. }
  13. if (!isset($_POST['authorized'])):
  14. require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/header.inc.php';
  15. ?>
  16. <div class="container">
  17. <div class="panel panel-default">
  18. <div class="panel-heading"><?=$lang['oauth2']['authorize_app'];?></div>
  19. <div class="panel-body">
  20. <?php
  21. if ($_SESSION['mailcow_cc_role'] != 'user'):
  22. $request = '';
  23. ?>
  24. <p><?=$lang['oauth2']['access_denied'];?></p>
  25. <?php
  26. else:
  27. ?>
  28. <p><?=$lang['oauth2']['scope_ask_permission'];?>:</p>
  29. <dl class="dl-horizontal">
  30. <dt><?=$lang['oauth2']['profile'];?></dt>
  31. <dd><?=$lang['oauth2']['profile_desc'];?></dd>
  32. </dl>
  33. <form class="form-horizontal" autocapitalize="none" autocorrect="off" role="form" method="post">
  34. <div class="form-group">
  35. <div class="col-sm-10 text-center">
  36. <button class="btn btn-success" name="authorized" type="submit" value="1"><?=$lang['oauth2']['permit'];?></button>
  37. <a href="#" class="btn btn-default" onclick="window.history.back()" role="button"><?=$lang['oauth2']['deny'];?></a>
  38. <input type="hidden" name="csrf_token" value="<?=$_SESSION['CSRF']['TOKEN'];?>">
  39. </div>
  40. </div>
  41. </form>
  42. <?php
  43. endif;
  44. ?>
  45. </div>
  46. </div>
  47. </div> <!-- /container -->
  48. <script src="../js/authorize.js"></script>
  49. <?php
  50. require_once $_SERVER['DOCUMENT_ROOT'] . '/inc/footer.inc.php';
  51. exit();
  52. endif;
  53. // print the authorization code if the user has authorized your client
  54. $is_authorized = ($_POST['authorized'] == '1');
  55. $oauth2_server->handleAuthorizeRequest($request, $response, $is_authorized, $_SESSION['mailcow_cc_username']);
  56. if ($is_authorized) {
  57. unset($_SESSION['oauth2_request']);
  58. header('Location: ' . $response->getHttpHeader('Location'));
  59. exit;
  60. }