Download the PHP package lingoda/b2b-crosslogin-bundle without Composer

On this page you can find all versions of the php package lingoda/b2b-crosslogin-bundle. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package b2b-crosslogin-bundle

Lingoda B2B Cross-Login Bundle

This bundle provides a way to cross-login between apps on B2B.

Installation

Then add the bundle to your config/bundles.php, if it is not added automatically:

Configuration

Add the following configuration to your config/packages/lingoda_cross_login.yaml:

!!! For security reasons, the audience of a generated token on one app has to match the issuer of the other app, and vice versa. Tokens that do not match this requirement will be rejected. The audience is automatically generated from the host and port of the URL provided.

The following statements should be true, in order to have a successful cross-login:

Configuration for LexikJWTAuthenticationBundle

Add the following configuration to your config/packages/lexik_jwt_authentication.yaml:

Configuring the firewall

Then, add the following configuration to your config/packages/security.yaml:

Configuring the routes

Finally, add the following to your config/routes.yaml:

Important note!

Usage in Twig

You can use the following Twig functions to generate JWT tokens and URLs:

Use cases

1. Bypassing JWT token authentication failure

If you don't want the authentication to fail if the JWT token is invalid, expired, or not provided, you can add the BypassFailureJWTAuthenticator to your firewall's custom_authenticators:

And register the authenticator in your config/services.yaml:

2. Stateful cross-login

If you want to make the cross-login stateful, add the jwt configuration to a stateful firewall, e.g.:

Receiving a cross-login

First decide whether you need this at all

If your receiving firewall is stateful, you do not. A JWT on a stateful firewall already authenticates the request and Symfony persists a session, so every URL is a valid landing page. That is use case #2 above. Change nothing.

You need a receive endpoint only when the receiving firewall is stateless: true. A stateless app has to exchange the short-lived cross-login token for its own durable credentials — typically cookies — and that exchange is app-specific. The bundle owns the route, the claim decoding and the failure shape, and dispatches events for the rest.

The receive side is off until you opt in, so upgrading cannot give an app an endpoint it did not ask for. Opting in takes two steps, per receiver.

1. Configure the receiver

Receivers are named because one app can receive on behalf of several hosts. Override jwt_manager when the app verifies cross-login tokens with a different key than it signs its own tokens with.

2. Import the route

The bundle does not register the route itself, because only your app knows the host constraint and the ordering — in an app with a catch-all route, this must be registered before that catch-all. The route is named receive, so name_prefix is required to keep several receivers distinct. Lingoda\CrossLoginBundle\Routing\CrossLoginRoutes::RECEIVE_PATH holds the recommended full path, for senders in other apps that cannot generate the route.

3. Give the route a firewall

PUBLIC_ACCESS is required: BypassFailureJWTAuthenticator lets an unusable token through instead of returning 401, so the controller can dispatch a failure your app can redirect on.

4. Listen

Three events fire, each under a name scoped to the receiver, so a listener in a multi-receiver app can never be triggered by a different receiver's hand-off.

Event name Object Use it to
lingoda_crosslogin.<receiver>.token_received CrossLoginTokenReceivedEvent inspect claims; setUser() to provision a user the app has not seen
lingoda_crosslogin.<receiver>.succeeded CrossLoginSucceededEvent setResponse() — mint your session and redirect
lingoda_crosslogin.<receiver>.failed CrossLoginFailedEvent setResponse() — usually a redirect to your own login

If no listener sets a Response the controller redirects to default_route, and on failure it adds the reason as a query parameter — ?crosslogin_error=invalid_token. The codes are missing_token, invalid_token and unknown_user (CrossLoginError). An exception message is never put in the URL.

Dependencies


All versions of b2b-crosslogin-bundle with dependencies

PHP Build Version
Package Version
Requires php Version ^8.3
lexik/jwt-authentication-bundle Version ^3.0
psr/log Version ^3.0
symfony/config Version ^6.4|^7.0|^8.0
symfony/dependency-injection Version ^6.4|^7.0|^8.0
symfony/event-dispatcher-contracts Version ^3.0
symfony/http-foundation Version ^6.4|^7.0|^8.0
symfony/http-kernel Version ^6.4|^7.0|^8.0
symfony/routing Version ^6.4|^7.0|^8.0
symfony/security-bundle Version ^6.4|^7.0|^8.0
twig/twig Version ^3.10
webmozart/assert Version ^1.11
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package lingoda/b2b-crosslogin-bundle contains the following files

Loading the files please wait ...