Commit b0e27b21 authored by eal's avatar eal
Browse files

Fix tootdon logins.

parent fa1f11e8
Pipeline #30 passed with stage
in 1 minute and 55 seconds
......@@ -40,7 +40,8 @@ def create_authorization(conn, %{"authorization" => %{"name" => name, "password"
# - proper scope handling
def token_exchange(conn, %{"grant_type" => "authorization_code"} = params) do
with %App{} = app <- Repo.get_by(App, client_id: params["client_id"], client_secret: params["client_secret"]),
%Authorization{} = auth <- Repo.get_by(Authorization, token: params["code"], app_id: app.id),
fixed_token = fix_padding(params["code"]),
%Authorization{} = auth <- Repo.get_by(Authorization, token: fixed_token, app_id: app.id),
{:ok, token} <- Token.exchange_token(app, auth) do
response = %{
token_type: "Bearer",
......@@ -50,6 +51,14 @@ def token_exchange(conn, %{"grant_type" => "authorization_code"} = params) do
scope: "read write follow"
}
json(conn, response)
else
_error -> json(conn, %{error: "Invalid credentials"})
end
end
defp fix_padding(token) do
token
|> Base.url_decode64!(padding: false)
|> Base.url_encode64
end
end
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment