php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #61691 OAuthProvider does not get encoded
Submitted: 2012-04-10 18:05 UTC Modified: 2012-08-24 09:01 UTC
Votes:2
Avg. Score:4.5 ± 0.5
Reproduced:2 of 2 (100.0%)
Same Version:1 (50.0%)
Same OS:1 (50.0%)
From: niels dot van dot hecke at gmail dot com Assigned:
Status: Open Package: oauth (PECL)
PHP Version: 5.3.10 OS: Ubuntu 10.04.4 LTS
Private report: No CVE-ID: None
View Add Comment Developer Edit
Anyone can comment on a bug. Have a simpler test case? Does it work for you on a different platform? Let us know!
Just going to say 'Me too!'? Don't clutter the database with that please — but make sure to vote on the bug!
Your email address:
MUST BE VALID
Solve the problem:
35 + 25 = ?
Subscribe to this entry?

 
 [2012-04-10 18:05 UTC] niels dot van dot hecke at gmail dot com
Description:
------------
When running a simple oauth consumer-provider script, signature mismatches occure because the sent signature (generated by the OAuth class) is encoded according to specifications but the calculated signature (generated by the OAuthProvider class) is not. Checking the two signatures causes errors and the authentication fails.
EG. consumer generates:3qBMmue4Q%2Bj8Dm4%2F9VSTl6y0TR8%3D
provider generates: 3qBMmue4Q+j8Dm4/9VSTl6y0TR8=

---
From manual page: http://www.php.net/oauthprovider.checkoauthrequest#refsect1-oauthprovider.checkoauthrequest-description
---



Patches

Add a Patch

Pull Requests

Add a Pull Request

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2012-08-21 17:57 UTC] hans at shapeways dot com
This seems related to what I'm seeing at https://bugs.php.net/bug.php?id=62882
 [2012-08-24 09:01 UTC] niels dot van dot hecke at gmail dot com
Hans,
Not really, because the consumer generated and provider generated strings are identical, just that the provider does not escape the string. I 'fixed' this by ULR encoding the string on the provider side and manually checking signatures.
 
PHP Copyright © 2001-2020 The PHP Group
All rights reserved.
Last updated: Fri Aug 07 18:01:27 2020 UTC