1. Go to this page and download the library: Download dlunire/dlauth library. Choose the download type require.
2. Extract the ZIP file and open the index.php.
3. Add this code to the index.php.
<?php
require_once('vendor/autoload.php');
/* Start to develop here. Best regards https://php-download.com/ */
dlunire / dlauth example snippets
declare(strict_types=1);
namespace App\Auth;
use DLAuth\Auth\DLAuth;
final class AppAuth extends DLAuth {
public function __construct(string $field = '__APP_AUTH__') {
parent::__construct(field: $field);
}
}
final class LoginController extends BaseController {
public function create(): void {
session_start(); // requerido antes de usar DLAuth
$auth = new AppAuth();
// Datos de contexto, opcionales, deben fijarse ANTES de crear la sesión
// IMPORTANTE: si no usa DLUnire, es posible que tengas que hacer lo que observas
// aquí abajo:
$auth->set_ip($_SERVER['REMOTE_ADDR'] ?? '')
->set_uri($_SERVER['REQUEST_URI'] ?? '');
// Si el login incluye 2FA ya resuelto por un proveedor externo
// (Google/Microsoft Authenticator, OTP por SMS/email):
// $auth->set_two_factor(true)->set_two_factor_token($otp_result->token);
$created = $auth->create_session_data([
'user_id' => $user->id,
'role' => $user->role,
]);
if (!$created) {
// Ya existía una sesión válida en este campo — comportamiento
// "write-once" deliberado de DLAuth. No se sobrescribe.
http_response_code(409);
return;
}
http_response_code(201);
}
}
final class ProfileController extends BaseController {
public function show(): void {
session_start();
$auth = new AppAuth();
$auth->authenticated(function ($session) {
// $session es un DLAuth\Data\SessionData
echo "Bienvenido, usuario #{$session->data['user_id']}";
});
$auth->unauthenticated(function () {
http_response_code(401);
});
}
}
$received_hash = $request->get_header('X-Session-Token'); // resuelto por DLRoute
if (!$auth->verify_token($received_hash)) {
http_response_code(401);
return;
}
$auth->logout(); // true si había una sesión y se eliminó
use DLAuth\Data\SessionsRemovalRequest;
$auth->delete_all_sessions(function () use ($user_id) {
// Este callback SOLO se ejecuta si el TTL ya expiró. Mientras la
// sesión esté dentro del rango configurado, ni siquiera se invoca —
// cero consultas a tu base de datos en el camino caliente.
$row = Revoke::where('user_uuid', $user_id)->first();
return (new SessionsRemovalRequest())
->set_key('revoke') // columna que indica revocación (1/0)
->capture_value($row);
});
$auth->delete_all_sessions(fn() =>
(new SessionsRemovalRequest())->set_key('revoke')->capture_value(['revoke' => 1])
);
use DLAuth\Context\Cookie;
use DLAuth\Enums\SameSite;
(new Cookie('session_token', $session->token))
->set_secure($is_https) // resuelto por DLRoute, no por Cookie
->set_same_site(SameSite::STRICT)
->set_expires(time() + 3600)
->dispatch();
Cookie::has('session_token'); // bool
Cookie::get('session_token'); // ?string
Cookie::remove('session_token'); // usa los mismos path/domain originales
Loading please wait ...
Before you can download the PHP files, the dependencies should be resolved. This can take some minutes. Please be patient.