Download the PHP package kingsoft/azure-oauth2 without Composer
On this page you can find all versions of the php package kingsoft/azure-oauth2. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download kingsoft/azure-oauth2
More information about kingsoft/azure-oauth2
Files in kingsoft/azure-oauth2
Package azure-oauth2
Short Description Handler to authenticate with AzureAD
License MIT
Informations about the package azure-oauth2
OAUTH2 authenticator for AzureAD
Security considerations
logoutAzure($redirectUrl) — open-redirect risk (severity: Low)
logoutAzure() appends $redirectUrl directly to the Microsoft
post_logout_redirect_uri query parameter. Microsoft validates this value
against the redirect URIs registered for your app, which limits exploitability.
However, if user-supplied input (e.g. from $_GET or $_POST) is ever passed
here, it becomes an open-redirect vector should that Azure-side validation be
misconfigured or loosened.
Rule: always pass a hard-coded or configuration-derived URL — never a caller/user-supplied value.
Requesting additional Graph scopes
By default the class only requests https://graph.microsoft.com/User.Read,
enough to resolve the signed-in user's profile for logon_callback. If your
app needs to make further Graph calls with the same delegated permissions
(e.g. reading group memberships), request the extra scope(s) before calling
requestAzureAdCode():
setScope() replaces the scope entirely instead of extending it — only use
it if you also want to drop the default User.Read scope.
logon_callback receives the raw token response as an optional second
argument, so it can use the access token for its own Graph calls within the
same request (there's no second round-trip, and nothing is persisted by this
class — store what you need in $_SESSION yourself if it must survive past
logon_callback):
Existing single-argument logon_callback implementations don't need to
change — PHP ignores the extra argument for callables that don't declare it.
Sample
Where config.php sets the global SETTINGS and logger LOG