OidcCallbackRequest
in package
implements
JsonSerializable
The `OidcCallbackRequest` schema from the server's OpenAPI document.
Table of Contents
Interfaces
- JsonSerializable
Properties
- $code : string
- $configId : string
- $nonce : string
- $redirectUri : string
- $state : string
Methods
- __construct() : mixed
- Constructs a OidcCallbackRequest.
- fromArray() : self
- Rebuilds a OidcCallbackRequest from one decoded JSON object.
- jsonSerialize() : array<string, mixed>
- Renders this object for `json_encode()`.
- toArray() : array<string, mixed>
- Renders this object back to its wire form.
Properties
$code read-only
public
string
$code
$configId read-only
public
string
$configId
$nonce read-only
public
string
$nonce
$redirectUri read-only
public
string
$redirectUri
$state read-only
public
string
$state
Methods
__construct()
Constructs a OidcCallbackRequest.
public
__construct(string $code, string $configId, string $nonce, string $redirectUri, string $state) : mixed
Parameters
- $code : string
-
Authorization code returned by the external IdP.
- $configId : string
-
ID of the federation config used in the authorization request.
- $nonce : string
-
Client-supplied nonce (SECHRD-07/D-04: retained for backward compatibility with older callers, but IGNORED for verification —
expected_noncealways comes from the server-sideFederationLoginStaterow looked up viastate, never from this field). - $redirectUri : string
-
Redirect URI that was used in the authorization request.
- $state : string
-
CSRF state value from the authorization request. Used to look up the server-side
FederationLoginStaterow that holds the real nonce (SECHRD-07/D-04) — required so the callback can find its login state.
fromArray()
Rebuilds a OidcCallbackRequest from one decoded JSON object.
public
static fromArray(array<string, mixed> $data) : self
Parameters
- $data : array<string, mixed>
-
The raw wire object.
Return values
selfjsonSerialize()
Renders this object for `json_encode()`.
public
jsonSerialize() : array<string, mixed>
Any Sensitive it carries stays WRAPPED here, so a log line or a
json_encode($model) in application code prints [SENSITIVE]. The one place a secret
is revealed is ManagementTransport, on the way to the wire
and nowhere else (§27.5).
Return values
array<string, mixed>toArray()
Renders this object back to its wire form.
public
toArray() : array<string, mixed>
§27.4 rule 5: a null property is OMITTED, not emitted as null. On a sparse update those two say opposite things — "leave this alone" versus "set this to nothing" — and only omission means the first.