leonmelis/uq_free 问题修复 & 功能扩展

解决BUG、新增功能、兼容多环境部署,快速响应你的开发需求

邮箱:yvsm@zunyunkeji.com | QQ:316430983 | 微信:yvsm316

leonmelis/uq_free

Composer 安装命令:

composer require leonmelis/uq_free

包简介

An unofficial PHP implementation for the Ubiqu Free API

README 文档

README

This is an unofficial PHP implementation for the Ubiqu Free API. The maintainer of this project is not affiliated with Ubiqu.

License: MIT

Installation

This library can easily be installed through Composer.

composer require leonmelis/uq_free

Then use it in your PHP code using:

require __DIR__ . '/vendor/autoload.php';

use \LeonMelis\UQ_free;

Requirements

  • PHP >= 5.6 or PHP >= 7.0
  • cURL PHP module (ext-curl)

NOTE: this library uses phpseclib internally. It is recommended (but not required) by phpseclib to have the PHP ext-openssl module installed for better performance.

Getting started

Before getting started, you should have the Ubiqu Authenticate app installed on a mobile device:

Then, create a new ServiceProvider:

$provider = UQ_free\ServiceProvider::create(
    'My Service Provider',
    'https://mydomain.com',
    'https://mydomain.com/callback'
);

echo "UUID: {$provider->getUuid()}\n";
echo "API key: '{$provider->getAPIKey()}'\n";
echo "Activate admin with nonce: '{$provider->getNonceFormatted()}'\n";

The ServiceProvider object is now created on the Ubiqu server, but not yet active. To activate the provider (and also become owner of it) use the Authenticate app on your mobile device, choose 'auto-activate' from the settings menu and enter the 9 digit nonce from the ServiceProvider object when prompted.

Store the API key and UUID for this provider.

A previously created ServiceProvider can be constructed by passing the UUID and API-key to the constructor:

$provider = new UQ_free\ServiceProvider($uuid, $api_key);

// Optionally, you can remote fetch the ServiceProvider object
// to get additional data, such as the name.
$provider->fetch(); 
echo "Using provider {$provider->getName()}\n";

Creating assets

An Asset is created through an Identification object. This may be confusing at first, but you have to remember that we don't know the device that will control the asset at this point in time.

The Identification object contains a nonce which can be entered in the Authenticate app. Once completed a callback is made from the Ubiqu Free API, notifying us that the identification has been consumed and the asset is ready to use.

// To create a new asset
$identification = $provider->createIdentification();
echo "Identify with: '{$identification->getNonceFormatted()}'\n";
// Wait for callback, then we can fetch the asset
$asset = $identification->fetchAsset();

Performing an AssetRequest

The AssetRequest allows to perform a cryptographic method on the private key owned by the end user. This is the heart of the Ubiqu system. The user gets a push-message on their mobile device, asking to approve or reject the request, unlocking their private key using their PIN. Since we have the public key we can validate the signature we receive.

/* Authentication */
$authentication_request = $asset->authenticate();
// Wait for callback
$verified = $authentication_request->verify();

/* Sign */
$sign_request = $asset->sign(hash($document));
// Wait for callback
$verified = $sign_request->verify();

/* Decrypt */
$decrypt_request = $asset->decrypt($encrypted_data);
// Wait for callback
$plain = $decrypt_request->getPlainText();

Creating a CSR

It is possible to create a CSR without possession of the private key. However, this is uncommon and requires knowledge of the CSR internal structure (ASN.1). So, a CSR class is added to help you with performing this procedure.

$csr = $asset->createCSR(['CommonName' => 'example.com']);
$csr->requestSign();
// Wait for callback
echo $csr->getSigned();

Callbacks

Due to the asynchronous nature of the Ubiqu Free protocol (waiting for the user to approve/reject the AssetRequest through the app) the Ubiqu Free API makes callbacks to the callback_url passed to the API during creation of the ServiceProvider. Ubiqu makes a callback every time an object owned by the ServiceProvider changes state.

To handle the callbacks, use the CallbackHandler class.

$handler = new CallbackHandler();
$handler->handleCallback($_POST);

The CallbackHandler constructor accepts a CacheInterface instance for persisting the received updates, of pushing the changes to some data bus.

Caching / persisting

By default, the Connector class uses a MemoryCache instance for caching. This prevents having to fetch the same object more than once from the API.

However, the MemoryCache is of limited use, due to the very nature of PHP being restarted on each call. Also, this Ubiqu Free library is fairly useless if objects cannot be persisted to something like a database.

To create your own caching/persistence class, all you need to do is implement the CacheInterface interface, consisting of 2 simple methods. Pass an instance of that class to the Connector constructor.

class MyCache implements UQ_free\CacheInterface {
    function read($type, $uuid) {
        return database_read($type, $uuid);
    }
    
    function write($type, $uuid, $data) {
        database_write($type, $uuid, $data);
    }
}

$connector = new UQ_free\Connector(new MyCache());
$provider = new UQ_free\ServiceProvider($uuid, $api_key, $connector);

The data is passed to the writer as a raw stdClass as received from the API. The reader is expected to return a stdClass instance or an associative array.

You don't necessarily need to store all fields of the UQObject instances, or even store every object type.

For all UQObject instances you should at least store the UUID and state (status_code). For an Asset you must also store the value of public_key. All other fields are currently not required for the functioning of this library.

More information

https://ubiqu.com/developers/ubiqu-free-tutorial/

https://ubiqu.com/developers/freetutorial-creating-service-providers/

leonmelis/uq_free 适用场景与选型建议

leonmelis/uq_free 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 6 次下载、GitHub Stars 达 0, 最近一次更新时间为 2018 年 06 月 01 日, 在 PHP 生态内属于活跃度较高的组件。

它主要适用于以下技术方向: 「php」 「api」 「authenticate」 「ubiqu」 「ubiqu free」 等业务场景。在实际项目中,围绕这些方向常见需要落地的问题包括:接口对接、性能调优、并发安全、与既有框架(Laravel / ThinkPHP / Yii / Webman 等)的兼容适配,以及生产环境的日志埋点与稳定性保障。

我们在过去多个企业项目中使用过 leonmelis/uq_free 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。

围绕 leonmelis/uq_free 我们能提供哪些服务?
定制开发 / 二次开发

基于 leonmelis/uq_free 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。

BUG 修复 & 性能优化

线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。

项目外包 & 长期维护

承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。

yvsm@zunyunkeji.com QQ:316430983 微信:yvsm316 西安尊云信息科技 · 专注 PHP / Go / 分布式系统研发

统计信息

  • 总下载量: 6
  • 月度下载量: 0
  • 日度下载量: 0
  • 收藏数: 0
  • 点击次数: 1
  • 依赖项目数: 0
  • 推荐数: 0

GitHub 信息

  • Stars: 0
  • Watchers: 1
  • Forks: 0
  • 开发语言: PHP

其他信息

  • 授权协议: MIT
  • 更新时间: 2018-06-01