Download the PHP package kylesean/hyperf-jwt without Composer
On this page you can find all versions of the php package kylesean/hyperf-jwt. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download kylesean/hyperf-jwt
More information about kylesean/hyperf-jwt
Files in kylesean/hyperf-jwt
Package hyperf-jwt
Short Description A JWT (JSON Web Token) package for Hyperf framework.
License MIT
Informations about the package hyperf-jwt
Hyperf JWT Package
English | 中文文档
A high-performance, lightweight JWT (JSON Web Token) package designed for Hyperf coroutine framework, powered by lcobucci/jwt v5.
Features
- Coroutine Friendly: Native integration with Hyperf DI container and Swoole/Swow coroutine concurrency environments.
- Multiple Algorithms: Full support for HMAC (HS256, HS384, HS512), RSA (RS256, etc.), and ECDSA (ES256, etc.) signing algorithms.
- Blacklist & Concurrency Grace Period: Redis/Cache-backed token blacklisting with an innovative Concurrency Grace Period mechanism for coroutine applications.
- Flexible Request Parsing: Extract tokens from Authorization Header (Bearer), URL Query Parameters, POST Body, or Cookies in customizable order.
- Seamless Authentication Middleware: Out-of-the-box
JwtAuthMiddlewarewith coroutine context isolation and convenient static helpers.
Installation
Install via Composer:
Publish the configuration file:
Generate a secure secret key:
Quick Start
1. Token Issuance & Parsing
2. Token Refreshing
The ManagerInterface::refreshToken() method allows clients to swap an expiring token for a fresh token within the configured refresh window (refresh_ttl), automatically blacklisting the old token.
3. Token Invalidation & Blacklist Grace Period
Manual Invalidation (Logout)
The blacklist entry for an invalidated token is kept until the token's natural expiry plus the full refresh_ttl window, so a logged-out token can never be "revived" by refreshing it later. Pass true as the second argument to keep the entry for one year ("forever") instead: $manager->invalidate($token, true).
Coroutine Concurrency Grace Period
In high-concurrency coroutine environments (e.g. 5 parallel HTTP requests sent by a Single Page App simultaneously), if one request refreshes the token and invalidates the old one immediately, the remaining 4 concurrent requests carrying the old token might trigger 401 Unauthorized errors.
Configure the concurrency grace period in config/autoload/jwt.php:
During this 30-second window, the replaced old token remains accepted as valid, preventing race-condition failures.
Concurrency semantics: the grace period guarantees that concurrent requests validating the old token do not fail. Blacklisting itself is a non-atomic check-then-set against the cache, so two refresh calls arriving at the exact same instant may both succeed and each receive a new token (the old token still ends up blacklisted). If your business logic requires strictly single-use refresh, add a distributed lock around
refreshToken().
4. Authentication Middleware
Register JwtAuthMiddleware in your routes or controller annotations:
Access authenticated identity inside controllers:
License
MIT license
All versions of hyperf-jwt with dependencies
lcobucci/jwt Version ^5.4
psr/clock Version ^1.0
hyperf/contract Version ^3.0 || ^3.1
hyperf/cache Version ^3.0 || ^3.1
hyperf/stringable Version ^3.0 || ^3.1
psr/simple-cache Version ^2.0 || ^3.0