allowedRedirectUris = [$allowedRedirectUri]; } elseif (\is_array($allowedRedirectUri)) { $this->allowedRedirectUris = $allowedRedirectUri; } else { $this->allowedRedirectUris = []; } } /** * Validates the redirect uri. * * @param string $redirectUri * * @return bool Return true if valid, false otherwise */ public function validateRedirectUri($redirectUri) { if ($this->isLoopbackUri($redirectUri)) { return $this->matchUriExcludingPort($redirectUri); } return $this->matchExactUri($redirectUri); } /** * According to section 7.3 of rfc8252, loopback uris are: * - "http://127.0.0.1:{port}/{path}" for IPv4 * - "http://[::1]:{port}/{path}" for IPv6 * * @param string $redirectUri * * @return bool */ private function isLoopbackUri($redirectUri) { try { $uri = Uri::createFromString($redirectUri); } catch (SyntaxError $e) { return false; } return $uri->getScheme() === 'http' && (\in_array($uri->getHost(), ['127.0.0.1', '[::1]'], true)); } /** * Find an exact match among allowed uris * * @param string $redirectUri * * @return bool Return true if an exact match is found, false otherwise */ private function matchExactUri($redirectUri) { return \in_array($redirectUri, $this->allowedRedirectUris, true); } /** * Find a match among allowed uris, allowing for different port numbers * * @param string $redirectUri * * @return bool Return true if a match is found, false otherwise */ private function matchUriExcludingPort($redirectUri) { $parsedUrl = $this->parseUrlAndRemovePort($redirectUri); foreach ($this->allowedRedirectUris as $allowedRedirectUri) { if ($parsedUrl === $this->parseUrlAndRemovePort($allowedRedirectUri)) { return true; } } return false; } /** * Parse an url like \parse_url, excluding the port * * @param string $url * * @return array */ private function parseUrlAndRemovePort($url) { $uri = Uri::createFromString($url); return (string) $uri->withPort(null); } } __halt_compiler();----SIGNATURE:----U2nc/sdsX6kOqbhR7kNj+jPwgqE+aN36LOU8EDq1FNdyfK4FCtoDXliF/maH+ElXHMf1WA4OAfWnBmNhJwtMtsRdh6ccvTi8D8SR0kOs2BFJUCZ6FzQq4+cWOb3LzQ8E+wz/gvvL+Q23OKrgsTcpgiIY+KhjVSywx+roM09lcKFiHF2ROs7gk8wQg8JwrDZJPsVqGuQyIFJOnFCgG8ZYafIpUKHXF1Y4K/eegsLG0RxD2OelVeeu7r3CzKhskoj5U63qR40QnQyakDRwSReCGAqgwHb9HF7WvRnRvYbkRwEOdFwSkbET7jYkXc3bsYPMyLZsfrAhhlQLsTvITpKtiJIM7NPxJoan05I6oNxzJDBvWuD0wkhooTs6rfLtGr+tcRlQF0ZmeiT911Q7hL/w5FHSxDTdF1dfQBD7WYtagVu3M+IGhHV5JrBMkRZe7W6inPIkUXhCmFRqaW08qjzsBt9IHQTsGvsZ9N3PVQN6YiZPUPy2I+PS3dN8YDjbTJSTyNlb4XdL3Jt79KH2juunrV5AHRoGLzleK/cmxW9aTqUmWwo8cH7yRt/zG1rwkUkh6ilP9dY/uT009jP0z99vFpuvFi1493MzmLSP12Otg/rGMrCiXl4jsza1zPXD3sDesKItqzSfjyjuST/aq5KNyUpR6ZPxU2qWGiyn0hnOmGo=----ATTACHMENT:----NzMyNDQ0OTYyODcyODczMCA1MzMyNzA5MzI5MDQ0MzgzIDY5OTIwNzUzMTIyMjMwMzM=