使用FOSOAuthServerBundle在postPersist上生成令牌

时间:2018-08-21 10:45:50

标签: php api symfony fosuserbundle fosoauthserverbundle

我正在尝试在注册时创建令牌。 我将FosUserBundle用作身份验证器,并将FOSOAuthServerBundle用作API。

当我手动生成令牌时,一切正常。但是我想在成功注册后自动生成它。因此,我创建了一个名为EventListener

TokenSetter

这是代码

class TokenSetter
{
protected $container;

public function __construct(ContainerInterface $container)
{
    $this->container = $container;
}

public function postPersist(LifecycleEventArgs $args)
{
    $user = $args->getEntity();

    if ($user instanceof Account) {
        $clientManager = $this->container->get('fos_oauth_server.client_manager.default');
        $client = $clientManager->createClient();
        $client->setRedirectUris(array('http://127.0.0.1:8000'));
        $client->setAllowedGrantTypes(array('password', 'refresh_token'));
        $clientManager->updateClient($client);

        $grantRequest = new Request(array(
            'client_id'  => $client->getPublicId(),
            'client_secret' => $client->getSecret(),
            'grant_type' => 'password',
            'username' => $user->getUsername(),
            'password' => $user->getPlainPassword()
        ));

        $tokenResponse = $this->container->get('fos_oauth_server.server')->grantAccessToken($grantRequest);

        $token = $tokenResponse->getContent();
    }
}
}

问题是$user->getPlainPassword()返回空值。创建后将导致“ invalid_request”。

是否可以通过其他方式获取普通密码或生成令牌?

1 个答案:

答案 0 :(得分:0)

我自己解决了。

有两种解决方法。

第一种方法是将password更改为client_credentials。这样,您在生成访问令牌时无需发送用户名和密码。不利的一面是user_id的值将设置为NULL

第二个解决方案是创建一个不同的侦听器。 (RegistrationListener)

您需要编辑UserEntity并添加一个TempPlainPass getter和setter。 基本上,您需要做的是将纯密码存储在数据库onRegistrationSuccess中,并在onRegistrationCompleted上创建一个带有用户名和密码的令牌

重要! 不要忘记在生成令牌后删除TempPlainPass

请参见下面的代码:

class RegistrationListener implements EventSubscriberInterface
{
protected $container;

public function __construct(ContainerInterface $container)
{
    $this->container = $container;
}


public static function getSubscribedEvents()
{
    return array(
        FOSUserEvents::REGISTRATION_SUCCESS => 'onRegistrationSuccess',
        FOSUserEvents::REGISTRATION_COMPLETED => 'onRegistrationCompleted',
    );
}

public function onRegistrationSuccess(FormEvent $event)
{
    $user = $event->getForm()->getData();
    $user->setTempPlainPass($user->getPlainPassword());
    $user->setRoles(array('ROLE_ADMIN'));
}

public function onRegistrationCompleted(FilterUserResponseEvent $event)
{
    $user = $event->getUser();
    $clientManager = $this->container->get('fos_oauth_server.client_manager.default');
        $client = $clientManager->createClient();
        $client->setRedirectUris(array('http://127.0.0.1:8000'));
        $client->setAllowedGrantTypes(array('password', 'refresh_token'));
        $clientManager->updateClient($client);

        $grantRequest = new Request(array(
            'client_id'  => $client->getPublicId(),
            'client_secret' => $client->getSecret(),
            'grant_type' => 'password',
            'username' => $user->getUsername(),
            'password' => $user->getTempPlainPass()
        ));

        $this->container->get('fos_oauth_server.server')->grantAccessToken($grantRequest);

        $em = $this->container->get('doctrine.orm.default_entity_manager');
        $update = $em->getRepository(Account::class)->findOneById($user->getId());
        $update->setTempPlainPass('');
        $em->flush();
}
}