Hello.

First of all thanks for this module. it's very useful for us. :)

Now I use this module into my project. I have D8 as backend solution and use angular front. I have native users, who login/register from angular and this module handle this perfectly.

But now I have a problem. I want to add my project some social auth. like fb/google/etc with this module (simple_oauth). For my case I create Drupal users into back and want to return access/refresh token to Angular.

I try to find out how can i crate tokens from user entity but can't find any right way.

I need to know it's possible to use this module in my social auth workflow and if it is, is there any way to achieve my goal?

Thanks for help.

Comments

gagosha created an issue. See original summary.

e0ipso’s picture

There is nothing special to do, just use one of the different available flows. Learn more at: http://cms.contentacms.io/help/tutorials?field_topic_value=OAuth2

m.abdulqader’s picture

Thank you e0ipso
Can you mention in high level how we can do that with social auth module?

Moniroaf’s picture

so... how we can use D8 as backend to register user by OAuth2 ?
anybody know about that?
BTY am using JSON API but it does not support registration so i see if OAuth can do it or not?
Thanks :)

m.abdulqader’s picture

For me I created custom grant type for OAuth that extend password grant.

Then I edited the validation to talk with Facebook to check the token.

Then check if the user returned from Facebook has a record ..

Done enjoy new grant type

e0ipso’s picture

@m.abdulqader that sounds really nice! Would you share the code so others can get inspired by it too? That would be a fantastic way to contribute back to this project.

ayalon’s picture

I am also interested how you did it @m.abdulqader

raphael apard’s picture

I am also interested @m.abdulqader

m.abdulqader’s picture

StatusFileSize
new6.36 KB

Attached my custom module, this was part of a large custom module so excuse if anything missed.

This module could be improved to be a bridge between social_auth and OAuth module.

raphael apard’s picture

Status: Active » Needs review

Thanks a lot @m.abdulqader, you rocks.

I will take a look soon as possible !

raphael apard’s picture

StatusFileSize
new12.32 KB

You are using social_auth. I use custom code to check if user exist and create on if not.
I add a hook alter to allow other module to load a specific user given the facebook token.

Maybe not the better solution. Anyway, this is working for me, thanks a lot for sharing your code.

chihada’s picture

thanks a lot for working on this issue, That's what I was looking for,

but I need more details please about how to use it ..

I've tried this:

after I got the access_token from facebook, I make a new post request as following:

the post url:
my-domain/oauth/token

the body:
{
"grant_type" = "facebook",
"client_id" = "the-id-of-some-client",
"client_secret" = "the-secret-of-client",
"facebook_token" = "the access token returned by facebook"
}

If am not mistaken, it should return a Bearer token to access on my backend, but unfortunately it doesn't work for me.

ziobudda’s picture

Have you found a solutions to return an access/refresh token ? I am exactly in the same situation.

kiss.jozsef’s picture

Hello,
tried to implement something custom but tried to use the password grant and it was not working because on social register to password, then i found this implementation which is working.

How to make it work:
1. download and install the module
2. create a custom module where you implement : mymodule_oauth_facebook_grant_user_alter(&$user, $facebook_token), where you can do something similar how it is now in the .api file or something else entirely just make sure the return User if its found.

Thanks for the module its was really helpfull.

joaogarin’s picture

@kiss.jozsef I am trying what you describe here but not really understand what I am suposed to do, I think I am missing some part that is not yet clicking maybe you can help me out ;) Can you describe the idea in general how it works? here is what I am trying :

1 ) Get the facebook token from facebook (via a web app, or something else)
2 ) Call drupal (which endpoint? oauth/token with a "facebook" grant_type?)
3 ) drupal exchanges the facebook token received (if belongs to a user) for the drupal token from simple_auth
4 ) app now has a token from simple_auth that can be used to talk to drupal

is this sort of the approach? Essentially what happens to me is I get a "invalid_credentials" error when calling the grant type "facebook" with that information, which seems like expects a username and password..but I guess thats not the idea with facebook / social logins.. :

grant_type : "facebook"
client_id : "my client id in drupal"
client_secret : "My client secret in drupal"
facebook_token: "the token received from facebook"

Cheers, this is a nice idea for a generic module with a common approach. As soon as I get it working would love to make it more generic and make it available

Thanks for the pointers anyway its getting me closer ;)

kiss.jozsef’s picture

@joaogarin:
yes those steps are okay:
1. you can get facebook token here: https://developers.facebook.com/tools/explorer/
2. oauth/token endpoint and yes facebook grant type
3. this part you have to write manually in your hook, you have to implement in a custom module hook_oauth_facebook_grant_user wwhich you can find in oauth_facebook_grant.api.php (you can basically copy the code from there to test it)

how to test it: in the try block remove everything and write only User::load($id); ($id an existing user id in your system) if this work then you have to write the logic for your needs
for example:
- create a new field for users where you save their id.
- in the try block write a query to check if user with given id exists
- if user doesn't exists then create the user and save their facebook id in the new field

e0ipso’s picture

Status: Needs review » Closed (outdated)

I'm closing this as part of issue queue cleanup. Please reopen if necessary.

dunghoanguit’s picture