Download the PHP package cornell-custom-dev/laravel-cu-auth without Composer
On this page you can find all versions of the php package cornell-custom-dev/laravel-cu-auth. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download cornell-custom-dev/laravel-cu-auth
More information about cornell-custom-dev/laravel-cu-auth
Files in cornell-custom-dev/laravel-cu-auth
Package laravel-cu-auth
Short Description A Laravel package for authentication and identity management at Cornell University
License MIT
Informations about the package laravel-cu-auth
CUAuth
Middleware for authorizing Laravel users.
- CUAuth SSO - Single sign-on and authorization middleware
- SAML PHP Toolkit integration
- Apache mod_shib integration
- AppTesters - Limit access to users in the
APP_TESTERSenvironment variable - Local Login - Allow Laravel users to log in with a local username and password
- Livewire Auth - Block unauthenticated Livewire update requests
Use Cases
- Single Sign-On: Protect routes with SSO (mod_shib or PHP SAML)
- Optionally log in SSO users to app user accounts
- AppTesters: Limit access on non-production sites to users in the
APP_TESTERSenvironment variable
Single Sign-On
Usage
See Authorization for details on how to log in remote users for local authorization.
See also: shibboleth configuration.
Routing
Any pages protected by middleware are automatically redirected to SSO. To directly trigger log in or log out, use the following routes (parameters are optional and will default to '/'):
- Login:
route('cu-auth.sso-login', ['redirect_url' => '/home']) - Logout:
route('cu-auth.sso-logout', ['return' => '/'])
Certs and Metadata (php-saml)
For using the PHP SAML Toolkit, the SAML keys and certs can be generated with the following command:
It is possible to have composer automatically install the keys on composer install by adding the following to the scripts section of composer.json, which will only install the keys if they do not already exist:
The default location for the SAML keys and certs is in storage/app/keys. This location is configurable in the config/cu-auth.php file or by setting the SAML_CERT_PATH in .env.
Local Testing (apache-shib)
For local testing where mod_shib is not available, the REMOTE_USER environment variable can be set to simulate
Shibboleth authentication. Note that APP_ENV must be set to "local" for this to work and the config cache must be cleared when REMOTE_USER is changed.
Identity and Authorization
Once authenticated via SSO, the user's identity is available via the IdentityManager, which can be accessed via the app container.
The SAML attributes available are based on the CIT-documented list: https://it.cornell.edu/shibboleth/shibboleth-faq.
User authorization
If the site should manage authorization for users in the application, set config('cu-auth.require_local_user') to true:
Requiring a local user triggers the CUAuthenticated event when a user is authenticated via single sign-on. The site must
register a listener for
the CUAuthenticated event. This listener should look up the user in the database and log them in or create a user
as needed.
AuthorizeUser is provided as a starting point for handling the CUAuthenticated event. It is simplistic and should be replaced with a site-specific implementation in the site code base. It demonstrates retrieving user data via the IdentityManager and creating a user if they do not exist.
Configuration
See config/cu-auth.php for configuration options, all of which can be set with environment variables.
To modify the default configuration, publish the configuration file:
To modify the PHP SAML Toolkit configuration, publish the configuration file:
AppTesters
Limits non-production access to users in the APP_TESTERS environment variable.
Usage
On non-production sites, the AppTesters middleware checks the "APP_TESTERS" environment variable for a comma-separated list of users. If a user is logged in and not in the list, the middleware will return an HTTP_FORBIDDEN response.
The field used for looking up users is netid by default. It is configured in config/cu-auth.php file as app_testers_field.
Local Login
For testing purposes, the environment variable "ALLOW_LOCAL_LOGIN" can be set to true to bypass the middleware for a currently authenticated user.
Livewire Auth
Blocks unauthenticated POST requests to /livewire/update, preventing anonymous users from interacting with Livewire components.
Usage
All versions of laravel-cu-auth with dependencies
ext-openssl Version *
illuminate/support Version ^12.0|^13.0
onelogin/php-saml Version ^4.3.2