mirror of
https://github.com/projectsend/projectsend.git
synced 2026-09-17 00:55:07 +00:00
6e47d76ba6
Client file sharing, rebuilt from the ground up: a private area per client, resumable uploads, folders, groups and categories, sharing with expiry dates and download limits, comments, file versions, an activity log, a REST API, and sixteen languages. This repository begins here. ProjectSend 2 was developed privately, and that development history is not published — the previous generation remains available, with its own history, at projectsend/legacy. Free software under the GNU General Public License v2, or (at your option) any later version.
37 lines
1.2 KiB
PHP
37 lines
1.2 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Modules\Identity\Social;
|
|
|
|
use Symfony\Component\HttpFoundation\RedirectResponse;
|
|
|
|
/**
|
|
* Talking to an identity provider.
|
|
*
|
|
* An interface with one production implementation, so the login flow can
|
|
* be tested without one — the same strategy LdapDirectory established,
|
|
* and for the same reason: everything above the wire is where the bugs
|
|
* would be. Whether an unverified address may reach an existing account,
|
|
* whether a subject beats an email, whether two-factor still challenges —
|
|
* none of that should need an OAuth server to exercise, and all of it is
|
|
* where v1 went wrong.
|
|
*/
|
|
interface SocialGateway
|
|
{
|
|
/**
|
|
* Begin the exchange: where to send the browser.
|
|
*/
|
|
public function redirect(SocialSettings $settings): RedirectResponse;
|
|
|
|
/**
|
|
* The identity this provider just asserted.
|
|
*
|
|
* Returns null for every failure — a mismatched state, a refused
|
|
* consent screen, an unreachable token endpoint, a response with no
|
|
* subject — because the caller must not be able to tell them apart
|
|
* and neither must the person signing in.
|
|
*/
|
|
public function identity(SocialSettings $settings): ?SocialIdentity;
|
|
}
|