Download the PHP package jardissupport/auth without Composer
On this page you can find all versions of the php package jardissupport/auth. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download jardissupport/auth
More information about jardissupport/auth
Files in jardissupport/auth
Package auth
Short Description Opaque token management, session handling, password hashing, and role-based access control for PHP DDD applications — framework-free, no JWT, no third-party runtime dependencies beyond PHP built-ins and the Jardis contract
License MIT
Homepage https://jardis.io
Informations about the package auth
Jardis Auth
Part of Jardis — the Domain-Driven Design platform for PHP. You model your domain; Jardis generates the production-ready hexagonal code (DTOs, Command/Query handlers, repositories, persistence). This package is part of the open-source foundation that generated code runs on.
Authentication and authorization without framework coupling. A focused RBAC for PHP covering opaque tokens, session management, password hashing, and role-based access control — designed for DDD applications. No HTTP layer, no JWT, no third-party runtime dependencies beyond PHP built-ins and the Jardis contract. Pure support package.
Why This Package?
- Four classes to learn —
SessionManager,PasswordHasher,Guard,PasswordAuthenticator. Everything else is data - Opaque tokens — server-side state, SHA-256 hashed storage, no JWT complexity
- Token rotation — automatic refresh with old-token revocation
- RBAC as Value Objects — policies are immutable, defined in code, not in a database
- No third-party runtime dependencies — PHP built-ins (
password_hash,random_bytes,hash,hash_equals) plus the Jardis contract
Installation
Quick Start
Create a Session
Verify & Refresh Tokens
Hash & Verify Passwords
Authorize with RBAC
Authenticate with Password
Invalidate Sessions
Token Store
The package defines TokenStoreInterface — you implement it in your infrastructure layer:
An InMemoryTokenStore is included in tests/Support/ for testing.
Password Hashing
Error Handling
| Exception | When |
|---|---|
AuthenticationException |
Authentication failed (base class) |
TokenExpiredException |
Token has expired |
TokenRevokedException |
Token was revoked |
InvalidCredentialException |
Invalid credentials provided |
UnauthorizedException |
Insufficient permissions (RBAC) |
Architecture
The user sees four orchestrators. Internally, each delegates to invokable handlers:
Each handler is an invokable object (__invoke) — independently testable, replaceable, composable. The orchestrators contain no business logic, only delegation.
Test Structure
Tests mirror the src/ directory:
Contracts
Requires jardissupport/contracts ^1.0 || ^2.0 (ab dieser Version). Defined in jardissupport/contracts — implement these in your infrastructure:
| Interface | Purpose |
|---|---|
TokenStoreInterface |
Token persistence: store, find, revoke, deleteExpired |
PasswordHasherInterface |
Hash, verify, needsRehash |
GuardInterface |
Permission check + authorize |
AuthenticatorInterface |
Authenticate credentials, return AuthResult |
Kernel Integration
Auth is wired directly — constructor injection, no framework hook. DomainKernel (the Koffer in jardiscore/kernel) exposes 11 accessors for cross-cutting infrastructure (cache, logger, database, HTTP client, mailer, filesystem, event dispatcher/registry), but no auth(): Auth is a support package you instantiate and wire yourself in your bounded context.
(Earlier docs described this as "no service hook in DomainApp" — DomainApp was removed in the Kernel-Entkopplung refactor. The fact is unchanged, only the vocabulary: today's Koffer is DomainKernel, consumed by the generated {Domain}Context.)
- TokenStore: Implement in infrastructure (database, Redis)
- Policy: Define as value object in application layer
- Guard: Instantiate in application layer, inject Policy
ENV Variables (optional)
This package does not read the process environment itself — no getenv/$_ENV/DotEnv call exists in src/. The names below are a suggested convention for values you read yourself in the consuming application and pass explicitly into the constructors/methods (e.g. AUTH_HASH_ALGO → the $algorithm argument of PasswordHasher, AUTH_TOKEN_LENGTH → the length argument when generating a Token).
What This Package Does NOT Do
- No JWT — opaque tokens only. JWT comes in v2 at the earliest
- No OAuth2/OIDC — no authorization server, no PKCE
- No HTTP layer — no cookies, no middleware, no
session_start() - No user management — no user model, no registration flow
- No rate limiting — brute-force protection is infrastructure concern
- No token persistence — only the interface. You implement the store
- No event dispatching — events are returned to the caller, not dispatched internally
Development
Documentation
Full documentation, guides, and API reference:
docs.jardis.io/en/support/auth
License
MIT License — free for any use, including commercial.
AI-Assisted Development
This package ships with a skill for Claude Code, Cursor, Continue, and Aider. Install it in your consuming project:
More details: https://docs.jardis.io/en/skills