feat: update Twitter auth to use confidential client flow with Basic authentication
This commit is contained in:
@@ -8,6 +8,7 @@ import 'package:real_estate_mobile/config/app_config.dart';
|
|||||||
/// Twitter OAuth 2.0 PKCE flow for mobile.
|
/// Twitter OAuth 2.0 PKCE flow for mobile.
|
||||||
class TwitterAuthService {
|
class TwitterAuthService {
|
||||||
static const _clientId = 'eWEzaDJ0al9lX1diOGY0ejRYeXM6MTpjaQ';
|
static const _clientId = 'eWEzaDJ0al9lX1diOGY0ejRYeXM6MTpjaQ';
|
||||||
|
static const _clientSecret = 'HadGMSRKKswfXOajbmggrnmLAn9cxJsl8GtFxGHqjX-CJ0A2Tu';
|
||||||
static const _scope = 'tweet.read users.read offline.access';
|
static const _scope = 'tweet.read users.read offline.access';
|
||||||
|
|
||||||
/// Derive redirect URI from API base URL (matches next-auth callback)
|
/// Derive redirect URI from API base URL (matches next-auth callback)
|
||||||
@@ -57,11 +58,11 @@ class TwitterAuthService {
|
|||||||
Future<Map<String, dynamic>?> exchangeCodeForUser(String code) async {
|
Future<Map<String, dynamic>?> exchangeCodeForUser(String code) async {
|
||||||
final dio = Dio();
|
final dio = Dio();
|
||||||
|
|
||||||
// Exchange code for access token (PKCE public client — client_id in body)
|
// Exchange code for access token (confidential client — Basic auth)
|
||||||
|
final credentials = base64Encode(utf8.encode('$_clientId:$_clientSecret'));
|
||||||
final tokenBody =
|
final tokenBody =
|
||||||
'code=${Uri.encodeComponent(code)}'
|
'code=${Uri.encodeComponent(code)}'
|
||||||
'&grant_type=authorization_code'
|
'&grant_type=authorization_code'
|
||||||
'&client_id=${Uri.encodeComponent(_clientId)}'
|
|
||||||
'&redirect_uri=${Uri.encodeComponent(_redirectUri)}'
|
'&redirect_uri=${Uri.encodeComponent(_redirectUri)}'
|
||||||
'&code_verifier=${Uri.encodeComponent(_codeVerifier)}';
|
'&code_verifier=${Uri.encodeComponent(_codeVerifier)}';
|
||||||
|
|
||||||
@@ -69,6 +70,9 @@ class TwitterAuthService {
|
|||||||
'https://api.twitter.com/2/oauth2/token',
|
'https://api.twitter.com/2/oauth2/token',
|
||||||
options: Options(
|
options: Options(
|
||||||
contentType: 'application/x-www-form-urlencoded',
|
contentType: 'application/x-www-form-urlencoded',
|
||||||
|
headers: {
|
||||||
|
'Authorization': 'Basic $credentials',
|
||||||
|
},
|
||||||
),
|
),
|
||||||
data: tokenBody,
|
data: tokenBody,
|
||||||
);
|
);
|
||||||
|
|||||||
Reference in New Issue
Block a user