-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathoauth_handler.cpp
More file actions
161 lines (133 loc) · 5.22 KB
/
oauth_handler.cpp
File metadata and controls
161 lines (133 loc) · 5.22 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
#include "oauth_handler.h"
#include <WiFi.h>
#include "utils.h"
OAuthHandler::OAuthHandler(const String& clientId, const String& clientSecret, const String& redirectUri)
: GOOGLE_CLIENT_ID(clientId),
GOOGLE_CLIENT_SECRET(clientSecret),
GOOGLE_REDIRECT_URI(redirectUri) {}
void OAuthHandler::begin(WebServer* server) {
preferences.begin("oauth", false);
refresh_token = loadRefreshToken();
serverAvailable = (server != nullptr);
if (serverAvailable) {
server->on("/oauth_callback", HTTP_GET, std::bind(&OAuthHandler::handleOAuthRequest, this, server));
server->on("/token", HTTP_POST, std::bind(&OAuthHandler::handleTokenRequest, this, server));
}
}
bool OAuthHandler::isAuthorized() {
refresh_token = loadRefreshToken();
return !refresh_token.isEmpty();
}
void OAuthHandler::handleOAuthRequest(WebServer* server) {
if (!serverAvailable) return;
if (server->hasArg("code")) {
String error;
if (exchangeAuthCode(server->arg("code"), error)) {
server->send(200, "text/html", "<h1>Authorization Successful!</h1><p>You can close this window.</p>");
} else {
server->send(400, "text/html", "<h1>Authorization Failed</h1><p>Error: " + error + "</p>");
}
} else {
String html = "<html><head><title>Google Calendar Authorization</title></head><body>";
html += "<h1>Authorize Bindicator</h1>";
html += "<p>Click the button below to authorize access to your Google Calendar:</p>";
html += "<a href='" + getAuthUrl() + "'><button>Authorize</button></a>";
html += "</body></html>";
server->send(200, "text/html", html);
}
}
String OAuthHandler::getAuthUrl() {
String deviceIP = WiFi.localIP().toString();
String state = "device_ip=" + Utils::urlEncode(deviceIP) + "&callback_path=/oauth_callback";
String url = AUTH_ENDPOINT;
url += "?client_id=" + GOOGLE_CLIENT_ID;
url += "&redirect_uri=" + Utils::urlEncode(GOOGLE_REDIRECT_URI);
url += "&response_type=code";
url += "&scope=" + Utils::urlEncode(SCOPE);
url += "&access_type=offline";
url += "&prompt=consent";
url += "&state=" + Utils::urlEncode(state);
return url;
}
bool OAuthHandler::exchangeAuthCode(const String& code, String& error) {
HTTPClient http;
http.begin(TOKEN_ENDPOINT);
http.addHeader("Content-Type", "application/x-www-form-urlencoded");
String post_data = "code=" + Utils::urlEncode(code);
post_data += "&client_id=" + GOOGLE_CLIENT_ID;
post_data += "&client_secret=" + GOOGLE_CLIENT_SECRET;
post_data += "&redirect_uri=" + Utils::urlEncode(GOOGLE_REDIRECT_URI);
post_data += "&grant_type=authorization_code";
int httpCode = http.POST(post_data);
if (httpCode == 200) {
String payload = http.getString();
DynamicJsonDocument doc(1024);
deserializeJson(doc, payload);
refresh_token = doc["refresh_token"].as<String>();
access_token = doc["access_token"].as<String>();
int expires_in = doc["expires_in"];
token_expiry = millis() + (expires_in * 1000);
Serial.println("Received refresh token: " + refresh_token);
preferences.begin("oauth", false);
bool saved = preferences.putString("refresh_token", refresh_token);
Serial.print("Saved refresh token status: ");
Serial.println(saved ? "SUCCESS" : "FAILED");
preferences.end();
http.end();
return true;
}
http.end();
return false;
}
bool OAuthHandler::getValidToken(String& token) {
if (access_token != "" && millis() < token_expiry) {
token = access_token;
return true;
}
if (refreshAccessToken()) {
token = access_token;
return true;
}
return false;
}
bool OAuthHandler::refreshAccessToken() {
if (refresh_token.length() == 0) return false;
HTTPClient http;
http.begin(TOKEN_ENDPOINT);
http.addHeader("Content-Type", "application/x-www-form-urlencoded");
String post_data = "client_id=" + GOOGLE_CLIENT_ID;
post_data += "&client_secret=" + GOOGLE_CLIENT_SECRET;
post_data += "&refresh_token=" + refresh_token;
post_data += "&grant_type=refresh_token";
int httpCode = http.POST(post_data);
if (httpCode == 200) {
String payload = http.getString();
DynamicJsonDocument doc(1024);
deserializeJson(doc, payload);
access_token = doc["access_token"].as<String>();
int expires_in = doc["expires_in"];
token_expiry = millis() + (expires_in * 1000);
http.end();
return true;
}
http.end();
return false;
}
void OAuthHandler::saveRefreshToken(const String& token) {
preferences.begin("oauth", false);
preferences.putString("refresh_token", token);
}
String OAuthHandler::loadRefreshToken() {
preferences.begin("oauth", false);
return preferences.getString("refresh_token", "");
}
void OAuthHandler::handleTokenRequest(WebServer* server) {
if (!serverAvailable) return;
if (server->hasArg("refresh_token")) {
String token = server->arg("refresh_token");
saveRefreshToken(token);
server->send(200, "text/plain", "OK");
} else {
server->send(400, "text/plain", "No refresh token provided");
}
}