'fail', 'message'=>'잘못된 인증번호']); // exit; // } // // 1. Descope API에 검증 요청 (curl 또는 file_get_contents) // $descope_project_id = "P2wON5fy1K6kyia269VpeIzYP8oP"; // $descope_api_url = "https://api.descope.com/v1/auth/otp/verify/email"; // email 인증 기준 // // $data = [ // // 'loginId' => $email, // 이메일 아이디 // // 'code' => $otp_code, // 입력받은 6자리 코드 // // ]; // // $headers = [ // // 'Content-Type: application/json', // // 'Accept: application/json', // // "x-descope-project-id: $descope_project_id" // // ]; // // $ch = curl_init(); // // curl_setopt($ch, CURLOPT_URL, $descope_api_url); // // curl_setopt($ch, CURLOPT_POST, true); // // curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($data)); // // curl_setopt($ch, CURLOPT_HTTPHEADER, $headers); // // curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); // // $response = curl_exec($ch); // // $http_code = curl_getinfo($ch, CURLINFO_HTTP_CODE); // // curl_close($ch); // // $res_data = json_decode($response, true); // // if ($http_code === 200 && isset($res_data['user'])) { // // // 인증 성공 // // echo json_encode(['status'=>'ok']); // // } else { // // // 실패, 에러 메시지 출력 // // $msg = $res_data['errorDescription'] ?? '인증 실패'; // // echo json_encode(['status'=>'fail', 'message'=>$msg]); // // } // $data = [ // 'loginId' => $email, // 'code' => $otp_code, // ]; // $headers = [ // 'Content-Type: application/json', // 'Authorization: Bearer ' . $descope_project_id, // ]; // $ch = curl_init('https://api.descope.com/v1/auth/otp/verify/email'); // curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); // curl_setopt($ch, CURLOPT_POST, true); // curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($data)); // curl_setopt($ch, CURLOPT_HTTPHEADER, $headers); // $response = curl_exec($ch); // $http_code = curl_getinfo($ch, CURLINFO_HTTP_CODE); // curl_close($ch); // $res_data = json_decode($response, true); // if ($http_code === 200 && isset($res_data['sessionJwt'])) { // // 인증 성공 // echo json_encode([ // 'status'=>'ok', // 'refreshJwt' => $res_data['refreshJwt'] ?? '', // ]); // } else { // // 인증 실패 // $msg = $res_data['errorDescription'] ?? '인증 실패'; // echo json_encode(['status'=>'fail', 'message'=>$msg]); // } // exit; ?> 'fail', 'message'=>'잘못된 입력']); exit; } // Descope 설정 $projectId = 'P2wON5fy1K6kyia269VpeIzYP8oP'; $managementKey = 'K32l5ORmzy32OvaaPvpdZsMY3JmKQb7a3vvrl10PgjlJUGk3K7EssMH3uW5VGQSbrgtEdPj'; // baron Access Key // 1. OTP 인증 요청 $data = [ 'loginId' => $email, 'code' => $otp_code, ]; $headers = [ 'Content-Type: application/json', 'Authorization: Bearer ' . $projectId, ]; $ch = curl_init('https://api.descope.com/v1/auth/otp/verify/email'); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($data)); curl_setopt($ch, CURLOPT_HTTPHEADER, $headers); $response = curl_exec($ch); $http_code = curl_getinfo($ch, CURLINFO_HTTP_CODE); curl_close($ch); // 응답 파싱 $res_data = json_decode($response, true); if ($http_code === 200 && isset($res_data['user'])) { $user = $res_data['user']; $userId = $user['userId'] ?? ''; $email = $user['email'] ?? ''; $refreshJwt = $res_data['refreshJwt'] ?? ''; // 도메인 분리 $domain = explode('@', $email)[1]; $internalDomains = [ "hanmaceng.co.kr", "samaneng.com", "jangheon.co.kr", "hallasanup.com", "pre-cast.co.kr", "baroncs.co.kr" ]; // 테넌트 결정 if (in_array($domain, $internalDomains)) { $tenantId = "T2wQcWCBhUfJgUWHWgNwLg4iUDVY"; // 내부 $isInternal = true; } else { $tenantId = "T2x4TDzxasp7auPCPcN8uOrxXchh"; // 외부 $isInternal = false; } // 2. 테넌트 연결 요청 $tenantPayload = [ "identifier" => $userId, "tenantId" => $tenantId, "roleNames" => ["Default User"] ]; $ch2 = curl_init('https://api.descope.com/v1/mgmt/user/update/tenant/add'); curl_setopt($ch2, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch2, CURLOPT_POST, true); curl_setopt($ch2, CURLOPT_POSTFIELDS, json_encode($tenantPayload)); curl_setopt($ch2, CURLOPT_HTTPHEADER, [ "Authorization: Bearer {$projectId}:{$managementKey}", "Content-Type: application/json" ]); $tenantRes = curl_exec($ch2); $tenantHttpCode = curl_getinfo($ch2, CURLINFO_HTTP_CODE); curl_close($ch2); // if ($tenantHttpCode !== 200) { // echo json_encode(['status'=>'fail', 'message'=>'테넌트 연결 실패', 'descope_response' => $tenantRes]); // exit; // } // ✅ 중복 연결은 오류로 간주하지 않음 if ($tenantHttpCode !== 200 && !str_contains($tenantRes, 'Tenant already exists')) { echo json_encode(['status'=>'fail', 'message'=>'테넌트 연결 실패', 'descope_response' => $tenantRes]); exit; } // 성공 응답 echo json_encode([ 'status' => 'ok', 'refreshJwt' => $refreshJwt, 'loginId' => $email, 'isInternal' => $isInternal ]); } else { $msg = $res_data['errorDescription'] ?? '인증 실패'; echo json_encode(['status'=>'fail', 'message'=>$msg]); } exit; ?>