Download the PHP package macpaw/composer-authenticated-repository-plugin without Composer
On this page you can find all versions of the php package macpaw/composer-authenticated-repository-plugin. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download macpaw/composer-authenticated-repository-plugin
More information about macpaw/composer-authenticated-repository-plugin
Files in macpaw/composer-authenticated-repository-plugin
Package composer-authenticated-repository-plugin
Short Description Composer plugin for authenticated repository access with GitHub tokens and HTTP basic auth
License MIT
Informations about the package composer-authenticated-repository-plugin
Composer Authenticated Repository Plugin
A Composer plugin that provides automatic authentication support for GitHub repositories and HTTP basic auth when downloading packages. The plugin intercepts file downloads and adds authentication headers as needed.
Features
- Pre-Download Hook: Intercepts file downloads using Composer's
PreFileDownloadEvent - GitHub Token Support: Automatic GitHub OAuth token injection for GitHub URLs
- HTTP Basic Auth: Support for HTTP basic authentication
- Repository Configuration: Configurable repository matching for authentication
- Debug Logging: Comprehensive debug output for troubleshooting
- Composer Config Integration: Uses existing Composer authentication configuration
- Transparent Operation: Works with existing Composer workflows
Installation
Option 1: Install as a Composer Plugin
Option 2: Manual Installation
- Clone this repository to your project
- Add the plugin to your
composer.json:
Configuration
1. Configure Authentication
First, configure your authentication credentials in Composer:
GitHub Token Authentication
HTTP Basic Authentication
2. Configure Repository Matching
Add configuration to composer extra section to specify which repositories should receive authentication:
Important: The owner and name fields are required and must match the GitHub repository owner and name exactly.
How It Works
1. Plugin Activation
The plugin activates during Composer initialization and:
- Reads authentication credentials from Composer configuration
- Creates an authenticated HTTP downloader
- Registers custom repository types
- Subscribes to the
PreFileDownloadEvent
2. Download Interception
When Composer attempts to download a file, the plugin:
3. Repository Matching
The plugin matches URLs against configured repositories:
4. Authentication Header Injection
For matching URLs, the plugin adds appropriate headers:
Environment Variables
For security, use environment variables:
Or use Composer's environment variable substitution:
Debug Mode
Enable debug logging to see what the plugin is doing:
The plugin will output debug information including:
- URLs being processed
- Whether authentication headers are needed
- Repository matching results
- Authentication header details
Security Considerations
- Token Security: Never commit authentication tokens to version control
- Environment Variables: Use environment variables for sensitive configuration
- Token Scopes: Use minimal required scopes for GitHub tokens
- HTTPS Only: All requests use HTTPS for security
- Repository Matching: Only URLs matching configured repositories receive authentication
Troubleshooting
Common Issues
-
401 Authentication Errors:
- Verify your tokens/credentials are correctly configured
- Check that the repository is configured in the plugin's
extrasection - Ensure the
ownerandnamematch the GitHub repository exactly
-
Repository Not Found:
- Ensure the repository URL is accessible with your credentials
- Verify the repository is listed in the plugin configuration
-
Package Not Found:
- Check that the package is listed in the repository manifest
- Verify download URLs are accessible with authentication
- Permission Denied:
- Verify your GitHub token has the required scopes
- Check repository visibility and access permissions
Debug Steps
-
Check authentication configuration:
-
Enable verbose output:
-
Test repository access:
- Verify plugin configuration:
Check that your
composer.jsonhas the correctextra.composer-authenticated-plugin.repositoriesconfiguration.
Development
Building the Plugin
Running Tests
Plugin Structure
License
MIT License - see LICENSE file for details.
Support
For issues and questions, please create an issue in the GitHub repository.
Current State and Recent Updates
Implementation Overview
The plugin currently implements authentication support through:
- PreFileDownloadEvent Hook: Intercepts all file downloads and adds authentication headers as needed
- Repository Matching: Only adds authentication for URLs matching configured repositories
- Debug Logging: Comprehensive debug output for troubleshooting
- GitHub Token Support: Automatic token injection for GitHub URLs
- HTTP Basic Auth: Support for HTTP basic authentication
Key Features
- Security: Repository-specific authentication prevents token exposure
- Compatibility: Works with existing Composer workflows
- Debugging: Extensive debug logging for troubleshooting
- Flexibility: Supports both GitHub tokens and HTTP basic auth
Recent Changes
- Repository Configuration: Now requires explicit repository configuration in
extra.composer-authenticated-plugin.repositories - Debug Logging: Added comprehensive debug output for troubleshooting
- URL Matching: Improved repository matching logic with case-insensitive comparison
- Documentation: Updated all README files to reflect current implementation
Known Limitations
- Only supports GitHub repositories and HTTP basic auth
- Requires explicit repository configuration
- Debug logging only available with
-vvvflag
Future Enhancements
- Support for additional authentication methods (OAuth 2.0, API keys)
- Caching and rate limiting support
- Enhanced error handling and retry logic
- Performance monitoring and metrics