commit: ed1eb5deea35ff2c3487ef550fad3a543a80cb32
parent: 7252f6b054dfdfac1f9bac77c442c5a1ebd898af
Author: lambda <pleromagit@rogerbraun.net>
Date: Mon, 6 Nov 2017 20:27:31 +0000
Merge branch 'fix-tootdon-oauth' into 'develop'
Fix tootdon logins.
See merge request pleroma/pleroma!6
Diffstat:
2 files changed, 11 insertions(+), 1 deletion(-)
diff --git a/README.md b/README.md
@@ -13,6 +13,7 @@ Mobile clients that are known to work well:
* Pawoo (Android + iOS)
* Subway Tooter
* Amaroq (iOS)
+* Tootdon (Android + iOS)
No release has been made yet, but several servers have been online for months already. If you want to run your own server, feel free to contact us at @lain@pleroma.soykaf.com or in our dev chat at https://matrix.heldscal.la/#/room/#pleromafe:matrix.heldscal.la.
diff --git a/lib/pleroma/web/oauth/oauth_controller.ex b/lib/pleroma/web/oauth/oauth_controller.ex
@@ -40,7 +40,8 @@ defmodule Pleroma.Web.OAuth.OAuthController do
# - proper scope handling
def token_exchange(conn, %{"grant_type" => "authorization_code"} = params) do
with %App{} = app <- Repo.get_by(App, client_id: params["client_id"], client_secret: params["client_secret"]),
- %Authorization{} = auth <- Repo.get_by(Authorization, token: params["code"], app_id: app.id),
+ fixed_token = fix_padding(params["code"]),
+ %Authorization{} = auth <- Repo.get_by(Authorization, token: fixed_token, app_id: app.id),
{:ok, token} <- Token.exchange_token(app, auth) do
response = %{
token_type: "Bearer",
@@ -50,6 +51,14 @@ defmodule Pleroma.Web.OAuth.OAuthController do
scope: "read write follow"
}
json(conn, response)
+ else
+ _error -> json(conn, %{error: "Invalid credentials"})
end
end
+
+ defp fix_padding(token) do
+ token
+ |> Base.url_decode64!(padding: false)
+ |> Base.url_encode64
+ end
end