Download the PHP package codebar-ag/laravel-microsoft-entra-sso without Composer
On this page you can find all versions of the php package codebar-ag/laravel-microsoft-entra-sso. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download codebar-ag/laravel-microsoft-entra-sso
More information about codebar-ag/laravel-microsoft-entra-sso
Files in codebar-ag/laravel-microsoft-entra-sso
Package laravel-microsoft-entra-sso
Short Description Microsoft Entra ID SSO authentication for Laravel via OAuth2 + OIDC
License MIT
Homepage https://github.com/codebar-ag/laravel-microsoft-entra-sso
Informations about the package laravel-microsoft-entra-sso
Microsoft Entra ID (Azure AD) SSO authentication package for Laravel using OAuth2 + OpenID Connect.
Requirements
- PHP 8.3, 8.4, or 8.5
- Laravel 13
- A Microsoft Entra app registration
Installation
Publish config (optional, recommended):
Publish package translations (recommended if you want to customize text or add locales):
Configuration
Set these environment variables:
Configure guards in config/microsoft-entra-sso.php:
The configured model must implement CodebarAg\MicrosoftEntraSSO\Contracts\SSOAuthenticatable (typically via the HasMicrosoftSSO trait).
Security and flow options
The package supports additional hardening options:
stateless: skips session-bound state validation (useful for API/mobile callback workflows).state_ttl_seconds: rejects stale OAuth state values.allowed_redirect_hosts: prevents redirect URI host misuse.
HTTP behavior
OAuth and Graph calls can be tuned:
Use these values to set environment-specific resiliency for slow networks or transient upstream failures.
Routes and controllers
The package registers two routes under the configured prefix (sso/microsoft by default):
GET /sso/microsoft/{guard}/redirect->RedirectToMicrosoftController(invokable)GET /sso/microsoft/{guard}/callback->HandleMicrosoftCallbackController(invokable)
Named routes remain:
microsoft-entra-sso.redirectmicrosoft-entra-sso.callback
Socialite-like API usage
The facade resolves a manager/factory contract and supports driver resolution similar to Socialite:
Under the hood the provider offers:
getAuthorizationUrl($state, $codeVerifier)exchangeCodeForTokens($code, $codeVerifier)getUserFromToken($token)refreshAccessToken($refreshToken)
Services and methods
Service resolution
Resolve the OAuth provider via facade/manager:
Resolve services directly from the container:
Provider API (OAuth)
stateless(bool $stateless = true): static- enable/disable session-less callback validation mode.getAuthorizationUrl(string $state, string $codeVerifier): string- build Microsoft authorize URL.exchangeCodeForTokens(string $code, string $codeVerifier): SSOToken- exchange callback code for tokens.getUserFromToken(string $accessToken): SSOUser- fetch current Microsoft user profile from Graph/me.refreshAccessToken(string $refreshToken): SSOToken- refresh an expired/expiring token.setRedirectUri(string $uri): static- override redirect URI at runtime.getRedirectUri(): ?string- inspect current redirect URI.
Static helpers on MicrosoftOAuthService:
generateState(): string- generate random OAuth state.generateCodeVerifier(): string- generate PKCE verifier.generateCodeChallenge(string $codeVerifier): string- derive PKCE S256 challenge.
Graph API helper service
getUserProfile(SSOAuthenticatable $user): array- extended profile fields from Microsoft Graph.getUserGroups(SSOAuthenticatable $user): Collection- all Azure AD groups for the user (handles pagination).getUserPhotoDataUri(SSOAuthenticatable $user): ?string- profile photo as data URI (nullwhen missing).isUserInGroup(SSOAuthenticatable $user, string $groupId): bool- efficient membership check (cache-aware).
Model trait API (HasMicrosoftSSO)
findByMicrosoftId(string $microsoftId): ?staticfindOrCreateFromMicrosoft(array $microsoftUser): staticlinkMicrosoftAccount(array $microsoftUser): voidupdateMicrosoftTokens(array $microsoftUser): voidhasMicrosoftSSOLinked(): boolisMicrosoftTokenExpired(): boolunlinkMicrosoftAccount(): void
Data objects
SSOToken helpers:
fromArray(array $payload): SSOTokentoArray(): array
SSOUser helpers:
fromGraphPayload(array $graphPayload): SSOUserwithToken(SSOToken $token): SSOUsertoArray(): array
Blade usage
Use the bundled button component in your login view:
You can override the label with a translation key:
Translations
The package ships with JSON translations for:
lang/en.jsonlang/de.json
After publishing (microsoft-entra-sso-translations), you can:
- edit existing keys in your application's
lang/en.jsonandlang/de.json - add additional locales by creating files like
lang/fr.jsonwith the same keys - set
APP_LOCALE(and optionallyAPP_FALLBACK_LOCALE) to control runtime language
Tailwind v4 (plain Tailwind, no Flux)
This package does not require Flux or any frontend UI dependency.
If you use the provided Blade component styles, ensure Tailwind v4 scans the package classes. Add a source path in your app stylesheet:
If your package is installed from vendor/, point @source at the vendor path instead:
Alternative: publish views and scan resources/views/vendor/microsoft-entra-sso/**/*.blade.php.
Events and extension points
The package dispatches:
CodebarAg\MicrosoftEntraSSO\Events\SSOUserRegisteredCodebarAg\MicrosoftEntraSSO\Events\SSOUserAuthenticated
Both events are emitted during the callback flow after the package authenticates or registers a user.
You can listen to these events to add:
- custom provisioning
- role/group synchronization
- audit logging
Troubleshooting
microsoft_entra_sso_errorin session:- Check Entra app credentials and callback URL.
- Ensure guard exists in
config/microsoft-entra-sso.php. - Ensure your app has a
loginroute (or fallback redirect handling in your app). - If state errors occur, verify callback happens within
state_ttl_seconds.
- Button appears unstyled:
- Verify Tailwind v4
@sourceincludes package Blade view paths. - Rebuild frontend assets after changing Tailwind sources.
- Verify Tailwind v4
Quality Checks
Run linting:
Run static analysis:
composer analyse runs PHPStan/Larastan using phpstan.neon.dist at level 9.
Run package tests:
Run coverage with enforced minimum:
All versions of laravel-microsoft-entra-sso with dependencies
illuminate/contracts Version ^13.0
illuminate/http Version ^13.0
illuminate/routing Version ^13.0
illuminate/support Version ^13.0