Download the PHP package formatd/hmac-authentication without Composer
On this page you can find all versions of the php package formatd/hmac-authentication. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download formatd/hmac-authentication
More information about formatd/hmac-authentication
Files in formatd/hmac-authentication
Package hmac-authentication
Short Description Neos Flow package that adds an authentication provider for authenticating a flow account using a token with a configurable timeout.
License MIT
Informations about the package hmac-authentication
FormatD.HmacAuthentication
This package adds an authentication provider for authenticating a flow account using a token with a configurable timeout. Authentication is done by passing username, timestamp and a hmac. For generating this token the package contains some viewhelpers and a Service.
Keep in mind: The token is usable multiple times and does not invalidate after usage. Only after a timeout.
Kompatiblität
Versioning scheme:
1.0.0
| | |
| | Bugfix Releases (non breaking)
| Neos Compatibility Releases (non breaking except framework dependencies)
Feature Releases (breaking)
Releases und compatibility:
Package-Version | Neos Flow Version |
---|---|
1.1.x | >= 6.x |
1.0.x | 4.x - 5.x |
Configure the Authentication Provider
In addition to your usual PersistedUsernamePasswordProvider you have to add a second UsernameHmacTimestampProvider provider to the configuration. Set the providerOption "mainAuthenticationProviderName" to the name of your PersistedUsernamePasswordProvider so that only the accounts of this provider can use the magic links.
Multiple AuthenticationProvider
To be able to use different AuthenticationProvider you have to add them to the allowedAuthenticationProviders
configuration and pass the AuthenticationProviderName as the second parameter.
Authentication on button click:
Authentication with a link (not encouraged):
Be Aware!
This is a very dangerous way to do authentication as the login-link is tracked for example in server logfiles or cached in proxies. Setting the timeout as low as possible is a must. Always prefer the submit button solution mentioned above.
OK, let me do this anyway
There are two ways how to generate a authentication link: Use one of the ViewHelpers...
...or use the hmacService directly in your code:
Using only AuthToken:
If you want to use the authToken in your code (for example to authenticate something else) just use the service class