kangaroorewards / oauth2-kangaroo-rewards
Kangaroo Rewards OAuth 2.0 Client Provider for The PHP League OAuth2-Client
Package info
github.com/kangaroorewards/oauth2-kangaroo-rewards
pkg:composer/kangaroorewards/oauth2-kangaroo-rewards
Requires
- php: ^8.1
- ext-curl: *
- ext-json: *
- league/oauth2-client: ^2.8
Requires (Dev)
- guzzlehttp/guzzle: ^7.9
- php-parallel-lint/php-parallel-lint: ^1.4
- phpunit/phpunit: ^10.5 || ^11.5 || ^12.0 || ^13.0
- squizlabs/php_codesniffer: ^3.11
Suggests
None
Provides
None
Conflicts
None
Replaces
None
README
This package provides Kangaroo Rewards OAuth 2.0 support for the PHP League's OAuth 2.0 Client.
This package is compliant with PSR-1, PSR-12, PSR-4, and PSR-7. If you notice compliance oversights, please send a patch via pull request.
Requirements
The following versions of PHP are supported.
- PHP 8.1
- PHP 8.2
- PHP 8.3
- PHP 8.4
- PHP 8.5
Requires the curl and json extensions, and league/oauth2-client ^2.8.
Running PHP 7.x or older? Stay on the
2.xreleases.
Installation
composer require kangaroorewards/oauth2-kangaroo-rewards:^3.0
Usage
Authorization Code Flow
session_start(); $provider = new KangarooRewards\OAuth2\Client\Provider\Kangaroo([ 'clientId' => CLIENT_ID, 'clientSecret' => CLIENT_SECRET, 'redirectUri' => REDIRECT_URI, ]); if (!isset($_GET['code'])) { // If we don't have an authorization code then get one $authUrl = $provider->getAuthorizationUrl([]); $_SESSION['oauth2state'] = $provider->getState(); echo '<a href="'.$authUrl.'">Log in with Kangaroo Rewards!</a>'; exit; // Check given state against previously stored one to mitigate CSRF attack } elseif (empty($_GET['state']) || ($_GET['state'] !== $_SESSION['oauth2state'])) { unset($_SESSION['oauth2state']); echo 'Invalid state.'; exit; } // Try to get an access token (using the authorization code grant) $token = $provider->getAccessToken('authorization_code', [ 'code' => $_GET['code'] ]); try { // We got an access token, let's make some requests $resourceOwner = $provider->getResourceOwner($token); $http = new GuzzleHttp\Client; $response = $http->get('https://api.kangaroorewards.com/customers', [ 'headers' => [ 'User-Agent' => '{Client Name}', 'Content-Type' => 'application/json', 'Accept' => 'application/vnd.kangaroorewards.api.v1+json;', 'Authorization' => 'Bearer ' . $token->getToken(), ] ]); $r = json_decode((string) $response->getBody(), true); echo '<pre>'; var_export($resourceOwner->toArray()); var_export($r); echo '</pre>'; } catch (Exception $e) { exit($e->getMessage()); } echo '<pre>'; // Use this to interact with the API on the client behalf var_dump($token->getToken()); echo '</pre>';
Grants
On top of the grants shipped with league/oauth2-client
(authorization_code, refresh_token, client_credentials, password), this
package registers two Kangaroo-specific grants:
// Requires: username, password $token = $provider->getAccessToken('facebook', [ 'username' => $email, 'password' => $facebookToken, ]); // Requires: username, google_token $token = $provider->getAccessToken('google', [ 'username' => $email, 'google_token' => $googleToken, ]);
Resource owner
$owner = $provider->getResourceOwner($token); $owner->getId(); $owner->getName(); $owner->getEmail(); $owner->getBusinessId(); $owner->getBusinessName(); $owner->toArray();
Every accessor returns null when the field is absent from the API response.
getBusinessId() and getBusinessName() read the business from the resource
owner response, and /me only returns it when asked. Point
urlResourceOwnerDetails at the include to populate them:
$provider = new KangarooRewards\OAuth2\Client\Provider\Kangaroo([ 'clientId' => CLIENT_ID, 'clientSecret' => CLIENT_SECRET, 'redirectUri' => REDIRECT_URI, 'urlResourceOwnerDetails' => 'https://api.kangaroorewards.com/me?include=business', ]);
Testing
composer install
composer test
composer lint
composer check
Auto-fix style issues with:
./vendor/bin/phpcbf src tests --standard=psr12 -p
Contributing
Please see CONTRIBUTING for details.
Credits
License
The MIT License (MIT). Please see License File for more information.