Include redirect_uri check on authorization endpoint

This commit is contained in:
İsmail BASKIN
2016-05-04 13:34:37 +03:00
parent 4a4f4fe2d7
commit 7285ede563
2 changed files with 50 additions and 0 deletions

View File

@@ -195,6 +195,11 @@ class AuthCodeGrant extends AbstractAuthorizeGrant
$this->getEmitter()->emit(new RequestEvent(RequestEvent::CLIENT_AUTHENTICATION_FAILED, $request));
throw OAuthServerException::invalidClient();
}
} elseif (is_array($client->getRedirectUri()) && count($client->getRedirectUri()) !== 1
|| empty($client->getRedirectUri())
) {
$this->getEmitter()->emit(new RequestEvent(RequestEvent::CLIENT_AUTHENTICATION_FAILED, $request));
throw OAuthServerException::invalidClient();
}
$scopes = $this->validateScopes(