Download the PHP package kingsoft/azure-oauth2 without Composer

On this page you can find all versions of the php package kingsoft/azure-oauth2. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package azure-oauth2

OAUTH2 authenticator for AzureAD

Security considerations

logoutAzure($redirectUrl) — open-redirect risk (severity: Low)

logoutAzure() appends $redirectUrl directly to the Microsoft post_logout_redirect_uri query parameter. Microsoft validates this value against the redirect URIs registered for your app, which limits exploitability. However, if user-supplied input (e.g. from $_GET or $_POST) is ever passed here, it becomes an open-redirect vector should that Azure-side validation be misconfigured or loosened.

Rule: always pass a hard-coded or configuration-derived URL — never a caller/user-supplied value.

Requesting additional Graph scopes

By default the class only requests https://graph.microsoft.com/User.Read, enough to resolve the signed-in user's profile for logon_callback. If your app needs to make further Graph calls with the same delegated permissions (e.g. reading group memberships), request the extra scope(s) before calling requestAzureAdCode():

setScope() replaces the scope entirely instead of extending it — only use it if you also want to drop the default User.Read scope.

logon_callback receives the raw token response as an optional second argument, so it can use the access token for its own Graph calls within the same request (there's no second round-trip, and nothing is persisted by this class — store what you need in $_SESSION yourself if it must survive past logon_callback):

Existing single-argument logon_callback implementations don't need to change — PHP ignores the extra argument for callables that don't declare it.

Sample

Where config.php sets the global SETTINGS and logger LOG


All versions of azure-oauth2 with dependencies

PHP Build Version
Package Version
Requires php Version >=8.2
kingsoft/http Version ^3.8
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package kingsoft/azure-oauth2 contains the following files

Loading the files please wait ...