Download the PHP package flownative/oauth2-client without Composer

On this page you can find all versions of the php package flownative/oauth2-client. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package oauth2-client

MIT license Packagist Maintenance level: Love

OAuth 2.0 Client for Flow Framework

This Flow package provides an OAuth 2.0 client SDK. Even though it can be used as a generic OAuth2 client, it was developed as a backing library for the OpenID Connect package. That's why documentation for this package is a bit sparse at the moment and examples for generic use are missing.

When upgrading from version 4, read the migration guide.

Authorizations

This package stores tokens as "authorizations" in a dedicated database table.

For example, the authorization code flow ends with a token, which is stored in the authorizations table. While the flow is in progress, this package keeps track of its "state" in the cache "Flownative_OAuth2_Client_State", in order to make sense of the incoming "finish authorization" request. Another example is the client credentials flow, where an access token is stored in the authorizations table which is needed for executing authorized requests to the respective service.

Token lifetime

An authorization expires together with its token. Expired authorizations are removed by the garbage collection.

Tokens which don't specify an expiration time get a default lifetime of 600 seconds (10 minutes). A token of the client credentials flow is replaced only when the new token was issued. An authorization code flow is stored as an authorization only when it finishes. Until then, it is kept in the state cache, where it expires after one hour.

The default token lifetime and the frequency of the garbage collection can be configured:

Note: By setting the defaultLifetime to null, tokens without an expiration time won't expire.

Instead of relying on chance, you can remove expired authorizations on a fixed schedule, for example with a cron job. Set the probability to 0 and run the following command regularly:

Authorization metadata

Authorizations also may contain developer-provided metadata. For example, you may attach an account identifier to an authorization when an authorization process starts and use that information when authorization finishes to make sure that the authorization is only used for a specific account (or customer number, or participant id).

Pass the metadata when you start the authorization code flow. It is stored together with the authorization when the flow finishes. The browser binding ties the authorization to the browser which starts it, so the response which redirects the browser must set its cookie. The client class provides the client secret in getClientSecret().

When the authorization is finished, the return URI contains a handle of the authorization. The handle can only be used once, within a minute and by the same browser. You may retrieve the metadata as follows:

To change the metadata of a finished authorization, use setAuthorizationMetadata().

Refused authorizations

If the OAuth server refuses an authorization, for example because the user denied access, the browser still returns to the return URI. Instead of the authorization id, the URI then contains the error code:

The error codes are the ones defined by RFC 6749 and OpenID Connect, for example access_denied. Any other code arrives as server_error.

Encryption

By default, access tokens are serialized and stored unencrypted in the "authorizations" database table. You can improve the security of your application by enabling the encrypted-at-rest feature of this package. When active, it encrypts tokens before storing them in the database and decrypts them automatically when they are retrieved. The secret key which is needed for encryption and decryption is not stored in the database.

This package uses the "ChaCha20-Poly1305-IETF" construction for authenticated encryption / decryption of serialized tokens, provided by the "sodium" PHP extension.

Generating a Secret Key

The OAuth2 Flow package provides a CLI command for generating encryption keys suitable for the currently supported encryption method:

The key is base64-encoded in order to simplify handling and being able to pass the key via Flow settings.

Enabling Encryption

Set the encryption key via Flow settings (for example in your global "Configuration/Settings.yaml"). Make sure to deploy this setting securely, for example by creating the Settings file during deployment or by using environment variables.

Verifying Encryption Configuration

When you have set the encryption key, test that everything is working as expected. Run your application so that a new authorization is created. Check the database table flownative_oauth2_client_authorization: the column serializedaccesstoken should be empty and the column encryptedserializedaccesstoken should contain a long string similar to this one:

There are three parts in this string, separated by two dollar signs:

  1. the construction used for encryption ("ChaCha20-Poly1305-IETF")
  2. the nonce used for this particular entry ("Mjdj4s9IFrPp6HFK")
  3. the encrypted data ("k9v3x…KQ==")

All versions of oauth2-client with dependencies

PHP Build Version
Package Version
Requires php Version 8.3.* || 8.4.* || 8.5.*
ext-sodium Version *
neos/flow Version ~8.3.13 || ~8.4.0 || ^9.0
guzzlehttp/guzzle Version ^7.9
league/oauth2-client Version ^2.9
ramsey/uuid Version ^4.7.6
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package flownative/oauth2-client contains the following files

Loading the files please wait ...