Download the PHP package chani/safi-auth without Composer
On this page you can find all versions of the php package chani/safi-auth. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Informations about the package safi-auth
Safi Auth Extension (safi-auth)
Authentication, session management, and brute-force protection extension for the Safi Microframework.
1. Quickstart
Installation
Service Provider Registration
Register AuthServiceProvider into the Assembler during application bootstrapping (init.inc.php):
Attach Authentication Middleware
Attach AuthMiddleware to your Kernel middleware pipeline:
Database Initialization
Execute the CLI command to create schema tables and the default admin record:
2. How-To Guides
Protecting Controller Routes
Routes are secure by default. Set public: true in the #[Route] attribute to grant unauthenticated access.
Handling Two-Factor Authentication (2FA / TOTP)
When a user with 2FA enabled attempts to log in, loginWithCredentials() returns false and dispatches a TwoFactorChallengeRequestedEvent.
To complete authentication or generate a setup QR code in your application/UI:
3. Reference
CLI Commands
auth:init: Creates database tables and initial admin record.auth:permissions-scan: Scans codebase for#[Permission]attributes and registers them in the database.auth:reset-password: Resets password for a given user email or identifier.
Endpoints
| URI | Method | Public | Name | Function |
|---|---|---|---|---|
/login |
GET |
Yes | auth.login.show |
Displays login form |
/login |
POST |
Yes | auth.login |
Authenticates credentials |
/login/2fa |
GET |
Yes | auth.login.2fa.show |
Displays 2FA challenge form |
/login/2fa |
POST |
Yes | auth.login.2fa |
Verifies 2FA challenge code |
/logout |
POST |
No | auth.logout |
Terminates active session |
4. Architecture & Concepts
- ORM & Database Agnostic:
safi-authdepends solely onsafi-corecontracts (DatabaseDriverInterfaceandModelInterface). It does not hardcode any ORM dependency and works seamlessly with any registered database driver. - Inverted Access Control: Unflagged routes are blocked by
AuthMiddleware. Access requires explicitpublic: trueroute metadata. - XHR & HTMX Behavior: Unauthenticated XHR/HTMX requests receive HTTP 401 with an
HX-Redirect: /loginheader instead of standard HTML redirects. - Brute-Force Shield:
BruteForceShieldlimits failed login attempts per IP/account using a PSR-16 cache backend or in-memory storage. - Audit Logging Boundary:
safi-authhandles core domain authentication events (UserLoggedInEvent,FailedLoginAttemptEvent,TwoFactorChallengeRequestedEvent,PermissionDeniedEvent,UserLoggedOutEvent). Admin UI mutation logging (e.g. user creation or permission modifications) is delegated exclusively tosafi-admin-panel.
License
MIT License. Author: Jean Bruenn
All versions of safi-auth with dependencies
chani/safi-core Version ^0.1.18
chani/safi-session Version ^0.1.5
psr/simple-cache Version ^3.0