【问题标题】:hybridauth 2.13.0 + Google authenticationhybridauth 2.13.0 + 谷歌认证
【发布时间】:2019-06-26 14:30:30
【问题描述】:

多年来,我一直在我的网站 (PHP 7.0) 上使用 hybridauth 进行社交登录。

我现在将其更新到 2.13.0 版(目前最新稳定版)

我确实设法配置并让 Facebook、Twitter、Linkedin 正常工作。

我被谷歌困住了。这里是配置:

"Google" => array(
                "enabled" => true,
                "keys" => array("id" => "$social_google_id", "secret" => "$social_google_secret"),   
                "scope" => "https://www.googleapis.com/auth/userinfo.profile https://www.googleapis.com/auth/userinfo.email"  
            ),

一切都很好,但当我收到消息时,Google 发回的重定向 url 似乎在服务器级别的路径中产生了误解:

Forbidden

You don't have permission to access /hybridauth/ on this server.
Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

url 字符串是: https://example.com/hybridauth/?hauth.done=Google&code=4/5QDkTNFvdiPkmQCct6m0bJ5Y_j0VjRSITw6EMn3NjyT6HPlrThx0iK5NrXkdxWnYoE0V_Y0ALV6iayHBuCb8Pk&scope=email+profile+https://www.googleapis.com/auth/userinfo.profile+https://www.googleapis.com/auth/userinfo.email

如果我把最后一部分剪成: https://example.com/hybridauth/?hauth.done=Google&code=4/5QDkTNFvdiPkmQCct6m0bJ5Y_j0VjRSITw6EMn3NjyT6HPlrThx0iK5NrXkdxWnYoE0V_Y0ALV6iayHBuCb8Pk&scope=email+profile

然后它起作用了,我从用户那里获取数据

我倾向于认为这与 Google 范围内的斜线有关。

知道如何排序吗?可能是 .htaccess 中的重写规则?

编辑

我再次检查,违规部分是“.profile”

事实上,如果我只指定电子邮件的范围,它就可以工作......问题是我还需要用户名...... 有什么想法吗?

这里是来自 Apache 的 error_log

[2019 年 2 月 2 日星期六 08:26:31.790178] [:error] [pid 4117:tid 47611986818816] [client 94.39.134.131:52882] [client 94.39.134.131] ModSecurity:使用代码 403 拒绝访问(阶段 2) . ARGS:scope 上的匹配短语“.profile”。 [文件“/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf”] [行“57”] [id“210580”] [rev“2”] [msg“COMODO WAF:操作系统文件访问尝试| |example.com|F|2"] [data "匹配数据:在 ARGS 中找到的 .profile:范围:电子邮件配置文件 https:/www.googleapis.com/auth/userinfo.email https:/www.googleapis.com/auth /userinfo.profile"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "example.com"] [uri "/hybridauth/"] [unique_id "BFVTJ0Unmh26fJ3XSeVQFeABAAE"],引用者:@ 987654323@

【问题讨论】:

    标签: php apache mod-rewrite oauth-2.0 hybridauth


    【解决方案1】:

    好的,对于遇到此问题的任何人,已确认这是服务器端设置。

    我联系了我的托管服务提供商,他们确认问题是误报:

    他们说:

    “阻止与 WAF mod_security 服务器端相关,可能会产生误报。我们排除了导致该行为的规则”

    完成后一切正常

    【讨论】:

      猜你喜欢
      • 2023-03-05
      • 1970-01-01
      • 2023-03-17
      • 2014-02-22
      • 2011-05-11
      • 2014-10-05
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多