Download the PHP package familysearch/fs-php-lite without Composer

On this page you can find all versions of the php package familysearch/fs-php-lite. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package fs-php-lite

FamilySearch PHP Lite SDK

Packagist Tests PHP Version

⚠️ Security Notice: Access tokens are stored in plaintext by default. Enable encryption in production. See Security Considerations.

Lite PHP SDK for the FamilySearch API.

Warning: this SDK requires hard-coding the API endpoint URLs. That is considered bad practice when using the API. In most cases, FamilySearch does not consider URL changes as breaking changes. Read more about dealing with change.

There is a sample app in the /examples directory that demonstrates SDK usage.

Environments

The SDK supports three FamilySearch environments:

Integration

Internal testing environment for FamilySearch developers and CI/CD pipelines. Not intended for external developer use.

Beta

Pre-production environment for testing upcoming API features and validating application compatibility before changes reach production.

Production

Live production environment with real FamilySearch user data.

Example:

Usage

Security Considerations

Session Token Encryption

⚠️ Important: By default, OAuth access tokens are stored in PHP $_SESSION in plaintext. This means tokens can be read by anyone with filesystem access to your server's session directory (typically /var/lib/php/sessions).

For production deployments, enable optional AES-256-GCM encryption to protect tokens at rest:

Generating an Encryption Key

Generate a secure 32-byte encryption key:

Key Storage Best Practices

✅ DO:

❌ DO NOT:

Example with environment variable:

What Encryption Protects

Session token encryption protects against:

What Encryption Does NOT Protect Against

Encryption is not a silver bullet. It does not protect against:

Bottom Line: Encryption protects data at rest. You also need HTTPS, secure session management, XSS protection, and proper server hardening.

Enabling Encryption on Existing Deployments

Enabling encryption on an existing application is seamless and backward-compatible. No downtime or manual migration required.

Step 1: Generate Encryption Key

Step 2: Store in Environment Variable

Step 3: Update SDK Configuration

Step 4: Deploy Changes

Deploy your updated application. No manual intervention needed.

Step 5: Automatic Migration

The migration happens automatically:

  1. Existing sessions with plaintext tokens continue to work (backward compatible)
  2. New OAuth flows store tokens encrypted
  3. When users re-authenticate, their tokens are encrypted automatically
  4. After natural session expiration (~24 hours), all tokens are encrypted

No forced logout. No disruption. No manual migration scripts required.

Verification

Verify encryption is working:

Additional Security Recommendations

  1. Enable HTTPS - Always use HTTPS in production
  2. Secure session cookies - Set session.cookie_secure = 1 in php.ini
  3. HTTPOnly cookies - Set session.cookie_httponly = 1 to prevent XSS
  4. SameSite cookies - Set session.cookie_samesite = "Strict" for CSRF protection
  5. Session directory permissions - Ensure session files are not world-readable:

  6. Regular key rotation - Rotate encryption keys every 90 days

For comprehensive security guidance, see SECURITY.md which includes:

Token Expiration Handling

The SDK provides comprehensive token expiration tracking and automatic re-authentication capabilities. FamilySearch access tokens expire based on two conditions (whichever comes first):

  1. Absolute Expiration: 24 hours from token creation
  2. Inactivity Expiration: 60 minutes since the last successful API call

The SDK tracks these conditions client-side and offers three flexible approaches to handle token expiration:

1. Proactive Expiration Checking

Check token expiration before making API requests:

2. Automatic Re-authentication Callback

Configure a callback to handle 401 responses automatically:

3. Enhanced Token Information

Retrieve detailed token metadata for custom handling:

Additional Features

Complete Documentation

For detailed documentation including additional examples, configuration options, and request replay behavior, see TOKEN_EXPIRATION.md

Serialization with gedcomx-php

When the objects configuration option is set to true, the gedcomx-php library can be used for serialization from objects for requests and deserialization into objects for responses.

When a response body is present, it will be deserialized as either an Atom Feed or a FamilySearchPlatform object.

gedcomx-php must be installed and included separately. gedcomx-php version 3.1.2 or later is required.

Testing

The SDK includes comprehensive unit and integration tests with 77.47% code coverage.

Quick Start

Test Suite Statistics

Test Structure

Integration Test Credentials

Integration tests require FamilySearch integration environment credentials. Set these environment variables:

How to get credentials:

  1. Visit https://developers.familysearch.org/
  2. Create an account and register an application
  3. Request integration environment access
  4. Use your integration credentials for testing

Running Tests on Specific PHP Versions

Viewing Coverage Reports

See TESTING.md for detailed instructions to create testing for your own application.

Requirements

Development

Contributing

  1. Fork the repository
  2. Create a feature branch
  3. Write tests for your changes
  4. Ensure all tests pass: composer test
  5. Submit a pull request

CI/CD

Tests run automatically via GitHub Actions on:

CI Status

See .github/workflows/tests.yml for CI configuration.

PHP Version Compatibility

Minimum: PHP 7.4
Tested: PHP 7.4, 8.0, 8.1, 8.2, 8.3, 8.4
Recommended: PHP 8.2+ for security updates

All tests pass on PHP 7.4-8.4 with zero deprecation warnings.


All versions of fs-php-lite with dependencies

PHP Build Version
Package Version
Requires php Version >=5.5
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package familysearch/fs-php-lite contains the following files

Loading the files please wait ...