GitHub.php 7.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197
  1. <?php
  2. /*
  3. * This file is part of Composer.
  4. *
  5. * (c) Nils Adermann <naderman@naderman.de>
  6. * Jordi Boggiano <j.boggiano@seld.be>
  7. *
  8. * For the full copyright and license information, please view the LICENSE
  9. * file that was distributed with this source code.
  10. */
  11. namespace Composer\Util;
  12. use Composer\IO\IOInterface;
  13. use Composer\Config;
  14. use Composer\Downloader\TransportException;
  15. use Composer\Json\JsonFile;
  16. /**
  17. * @author Jordi Boggiano <j.boggiano@seld.be>
  18. */
  19. class GitHub
  20. {
  21. protected $io;
  22. protected $config;
  23. protected $process;
  24. protected $remoteFilesystem;
  25. /**
  26. * Constructor.
  27. *
  28. * @param IOInterface $io The IO instance
  29. * @param Config $config The composer configuration
  30. * @param ProcessExecutor $process Process instance, injectable for mocking
  31. * @param RemoteFilesystem $remoteFilesystem Remote Filesystem, injectable for mocking
  32. */
  33. public function __construct(IOInterface $io, Config $config, ProcessExecutor $process = null, RemoteFilesystem $remoteFilesystem = null)
  34. {
  35. $this->io = $io;
  36. $this->config = $config;
  37. $this->process = $process ?: new ProcessExecutor;
  38. $this->remoteFilesystem = $remoteFilesystem ?: new RemoteFilesystem($io, $config);
  39. }
  40. /**
  41. * Attempts to authorize a GitHub domain via OAuth
  42. *
  43. * @param string $originUrl The host this GitHub instance is located at
  44. * @return bool true on success
  45. */
  46. public function authorizeOAuth($originUrl)
  47. {
  48. if (!in_array($originUrl, $this->config->get('github-domains'))) {
  49. return false;
  50. }
  51. // if available use token from git config
  52. if (0 === $this->process->execute('git config github.accesstoken', $output)) {
  53. $this->io->setAuthentication($originUrl, trim($output), 'x-oauth-basic');
  54. return true;
  55. }
  56. return false;
  57. }
  58. /**
  59. * Authorizes a GitHub domain interactively via OAuth
  60. *
  61. * @param string $originUrl The host this GitHub instance is located at
  62. * @param string $message The reason this authorization is required
  63. * @throws \RuntimeException
  64. * @throws TransportException|\Exception
  65. * @return bool true on success
  66. */
  67. public function authorizeOAuthInteractively($originUrl, $message = null)
  68. {
  69. $attemptCounter = 0;
  70. $apiUrl = ('github.com' === $originUrl) ? 'api.github.com' : $originUrl . '/api/v3';
  71. if ($message) {
  72. $this->io->write($message);
  73. }
  74. $this->io->write('The credentials will be swapped for an OAuth token stored in '.$this->config->getAuthConfigSource()->getName().', your password will not be stored');
  75. $this->io->write('To revoke access to this token you can visit https://github.com/settings/applications');
  76. while ($attemptCounter++ < 5) {
  77. try {
  78. if (empty($otp) || !$this->io->hasAuthentication($originUrl)) {
  79. $username = $this->io->ask('Username: ');
  80. $password = $this->io->askAndHideAnswer('Password: ');
  81. $otp = null;
  82. $this->io->setAuthentication($originUrl, $username, $password);
  83. }
  84. // build up OAuth app name
  85. $appName = 'Composer';
  86. if (0 === $this->process->execute('hostname', $output)) {
  87. $appName .= ' on ' . trim($output);
  88. }
  89. $headers = array();
  90. if ($otp) {
  91. $headers = array('X-GitHub-OTP: ' . $otp);
  92. }
  93. // try retrieving an existing token with the same name
  94. $contents = null;
  95. $auths = JsonFile::parseJson($this->remoteFilesystem->getContents($originUrl, 'https://'. $apiUrl . '/authorizations', false, array(
  96. 'retry-auth-failure' => false,
  97. 'http' => array(
  98. 'header' => $headers
  99. )
  100. )));
  101. foreach ($auths as $auth) {
  102. if (
  103. isset($auth['app']['name'])
  104. && 0 === strpos($auth['app']['name'], $appName)
  105. && $auth['app']['url'] === 'https://getcomposer.org/'
  106. ) {
  107. $this->io->write('An existing OAuth token for Composer is present and will be reused');
  108. $contents['token'] = $auth['token'];
  109. break;
  110. }
  111. }
  112. // no existing token, create one
  113. if (empty($contents['token'])) {
  114. $headers[] = 'Content-Type: application/json';
  115. $contents = JsonFile::parseJson($this->remoteFilesystem->getContents($originUrl, 'https://'. $apiUrl . '/authorizations', false, array(
  116. 'retry-auth-failure' => false,
  117. 'http' => array(
  118. 'method' => 'POST',
  119. 'follow_location' => false,
  120. 'header' => $headers,
  121. 'content' => json_encode(array(
  122. 'scopes' => array('repo'),
  123. 'note' => $appName,
  124. 'note_url' => 'https://getcomposer.org/',
  125. )),
  126. )
  127. )));
  128. $this->io->write('Token successfully created');
  129. }
  130. } catch (TransportException $e) {
  131. if (in_array($e->getCode(), array(403, 401))) {
  132. // 401 when authentication was supplied, handle 2FA if required.
  133. if ($this->io->hasAuthentication($originUrl)) {
  134. $headerNames = array_map(function ($header) {
  135. return strtolower(strstr($header, ':', true));
  136. }, $e->getHeaders());
  137. if ($key = array_search('x-github-otp', $headerNames)) {
  138. $headers = $e->getHeaders();
  139. list($required, $method) = array_map('trim', explode(';', substr(strstr($headers[$key], ':'), 1)));
  140. if ('required' === $required) {
  141. $this->io->write('Two-factor Authentication');
  142. if ('app' === $method) {
  143. $this->io->write('Open the two-factor authentication app on your device to view your authentication code and verify your identity.');
  144. }
  145. if ('sms' === $method) {
  146. $this->io->write('You have been sent an SMS message with an authentication code to verify your identity.');
  147. }
  148. $otp = $this->io->ask('Authentication Code: ');
  149. continue;
  150. }
  151. }
  152. }
  153. $this->io->write('Invalid credentials.');
  154. continue;
  155. }
  156. throw $e;
  157. }
  158. $this->io->setAuthentication($originUrl, $contents['token'], 'x-oauth-basic');
  159. // store value in user config
  160. $this->config->getConfigSource()->removeConfigSetting('github-oauth.'.$originUrl);
  161. $this->config->getAuthConfigSource()->addConfigSetting('github-oauth.'.$originUrl, $contents['token']);
  162. return true;
  163. }
  164. throw new \RuntimeException("Invalid GitHub credentials 5 times in a row, aborting.");
  165. }
  166. }