Bug 1597933 - clean up OAuth2 code: remove responseType which is always code.

Response type token is part of the OAuth 2.0 Implicit Flow which is not used in Mail Applications, but also discouraged by the OAuth Working Group: https://developer.okta.com/blog/2019/05/01/is-the-oauth-implicit-flow-dead
This commit is contained in:
Gaming4JC 2019-12-30 09:33:56 -05:00 committed by Roy Tam
commit 9839bd3335

View file

@ -3,7 +3,8 @@
* You can obtain one at http://mozilla.org/MPL/2.0/. */
/**
* Provides OAuth 2.0 authentication
* Provides OAuth 2.0 authentication.
* @see RFC 6749
*/
var EXPORTED_SYMBOLS = ["OAuth2"];
@ -41,8 +42,6 @@ OAuth2.CODE_AUTHORIZATION = "authorization_code";
OAuth2.CODE_REFRESH = "refresh_token";
OAuth2.prototype = {
responseType: "code",
consumerKey: null,
consumerSecret: null,
completionURI: "http://localhost",
@ -79,7 +78,7 @@ OAuth2.prototype = {
requestAuthorization: function requestAuthorization() {
let params = [
["response_type", this.responseType],
["response_type", "code"],
["client_id", this.consumerKey],
["redirect_uri", this.completionURI],
];
@ -173,13 +172,11 @@ OAuth2.prototype = {
onAuthorizationReceived: function(aData) {
this.log.info("authorization received" + aData);
let results = parseURLData(aData);
if (this.responseType == "code" && results.code) {
if (results.code) {
this.requestAccessToken(results.code, OAuth2.CODE_AUTHORIZATION);
} else if (this.responseType == "token") {
this.onAccessTokenReceived(JSON.stringify(results));
}
else
} else {
this.onAuthorizationFailed(null, aData);
}
},
onAuthorizationFailed: function(aError, aData) {