Skip to content

[ticket/17197] Replace OAuth library - #7045

Open
CHItA wants to merge 1 commit into
phpbb:masterfrom
CHItA:ticket/17197
Open

CHItA wants to merge 1 commit into
phpbb:masterfrom
CHItA:ticket/17197

Conversation

@CHItA

@CHItA CHItA commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

PHPBB3-17197

Checklist:

  • Correct branch: master for new features; 3.3.x for fixes
  • Tests pass
  • Code follows coding guidelines: master and 3.3.x
  • Commit follows commit message format

Tracker ticket:

https://tracker.phpbb.com/browse/PHPBB-12345

@private-packagist

private-packagist Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

phpBB/composer.lock

Package changes

Package Operation From To About
league/oauth2-client add - 2.9.1 view code - License: MIT License
composer/ca-bundle upgrade 1.5.12 1.5.14 diff
composer/composer upgrade 2.10.2 ⚠️ 2.10.3 ✅ diff
guzzlehttp/guzzle upgrade 7.14.0 ⚠️ 7.15.5 ✅ diff
guzzlehttp/promises upgrade 2.5.1 2.5.3 diff
guzzlehttp/psr7 upgrade 2.12.4 2.13.1 diff
justinrainbow/json-schema upgrade 6.10.0 6.12.0 diff
paragonie/sodium_compat upgrade v2.5.0 ⚠️ v2.5.2 ✅ diff
seld/phar-utils upgrade 1.2.1 1.2.2 diff
carlos-mg89/oauth remove 0.8.17 - -

Dev Package changes

Package Operation From To About
squizlabs/php_codesniffer upgrade 4.0.1 ⚠️ 4.0.4 ✅ diff

Settings · Docs · Powered by Private Packagist

@CHItA
CHItA force-pushed the ticket/17197 branch 2 times, most recently from 6fd4028 to 082ae9e Compare September 18, 2026 15:13
@private-packagist

Copy link
Copy Markdown

The composer.lock diff comment has been updated to reflect new changes in this PR.

@CHItA
CHItA force-pushed the ticket/17197 branch 2 times, most recently from b60c509 to b4d2f0c Compare September 18, 2026 16:13
@CHItA
CHItA requested a review from marc1706 September 19, 2026 08:22
@CHItA CHItA added 4.0 (Triton) 🔮 dependencies Pull requests that update a dependency file labels Sep 19, 2026
Comment thread phpBB/phpbb/auth/provider/oauth/provider/bitly.php

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Add a migration to remove the twitter oauth settings from the config

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it should be included in the migration - but will double check.

@marc1706 marc1706 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the lang string in common.php for the twitter oauth provider can also be removed now. Did you already tests this against google, etc. if oauth still works?

Comment thread phpBB/composer.json
"doctrine/dbal": "^4.4",
"google/recaptcha": "~1.1",
"guzzlehttp/guzzle": " ^7.0",
"league/oauth2-client": "2.*",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How about something like

Suggested change
"league/oauth2-client": "2.*",
"league/oauth2-client": "^2.8",

or even 2.9

<value>897a897b797c8789997d7979879</value>
<value>auth.provider.oauth.service.google</value>
<value>{"accessToken":"ya29.YPHwCWVkrvwu1kgbYKiDNYaQ451ZuHy9OEQAGVME8if-WBzR-v7a9ftxbx41kaL)5VLEXB-6qJEvri","endOfLife":1429959670,"extraParams":{"token_type":"Bearer","id_token":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiYWRtaW4iOnRydWUsImlhdCI6MTUxNjIzOTAyMn0.KMUFsIDTnFmyG3nMiGM6H9FNFUROf3wh7SmqJp-QV30"},"refreshToken":null,"token_class":"OAuth\\\\OAuth2\\\\Token\\\\StdOAuth2Token"}</value>
<value>{"access_token":"ya29.YPHwCWVkrvwu1kgbYKiDNYaQ451ZuHy9OEQAGVME8if-WBzR-v7a9ftxbx41kaL)5VLEXB-6qJEvri","expires":1429959670,"refresh_token":null,"values":{"token_type":"Bearer","id_token":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiYWRtaW4iOnRydWUsImlhdCI6MTUxNjIzOTAyMn0.KMUFsIDTnFmyG3nMiGM6H9FNFUROf3wh7SmqJp-QV30"}}}</value>

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
<value>{"access_token":"ya29.YPHwCWVkrvwu1kgbYKiDNYaQ451ZuHy9OEQAGVME8if-WBzR-v7a9ftxbx41kaL)5VLEXB-6qJEvri","expires":1429959670,"refresh_token":null,"values":{"token_type":"Bearer","id_token":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiYWRtaW4iOnRydWUsImlhdCI6MTUxNjIzOTAyMn0.KMUFsIDTnFmyG3nMiGM6H9FNFUROf3wh7SmqJp-QV30"}}}</value>
<value>{"access_token":"ya29.YPHwCWVkrvwu1kgbYKiDNYaQ451ZuHy9OEQAGVME8if-WBzR-v7a9ftxbx41kaL)5VLEXB-6qJEvri","expires":1429959670,"refresh_token":null,"values":{"token_type":"Bearer","id_token":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiYWRtaW4iOnRydWUsImlhdCI6MTUxNjIzOTAyMn0.KMUFsIDTnFmyG3nMiGM6H9FNFUROf3wh7SmqJp-QV30"}}</value>

$credentials = $this->get_service_credentials();

return [
'clientId' => $credentials['key'],

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Erm, those don't seem to be the same as the generic provider getRequiredOptions?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So for base get_provider() it will always throw. is there even a point of having the base method then?

* @var AbstractProvider service OAuth service
* @since 3.2.3-RC1
* @changed 3.2.6-RC1 Added redirect_data
* @psalm-var string[] $vars

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

maybr add a changed here since this is no longer the same type?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

4.0 (Triton) 🔮 dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants