Download the PHP package methorz/jwt-auth-middleware without Composer
On this page you can find all versions of the php package methorz/jwt-auth-middleware. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download methorz/jwt-auth-middleware
More information about methorz/jwt-auth-middleware
Files in methorz/jwt-auth-middleware
Package jwt-auth-middleware
Short Description PSR-15 JWT authentication middleware with zero-config approach. Supports HS256/RS256, Bearer/custom headers, optional user loading, and scope validation.
License MIT
Informations about the package jwt-auth-middleware
JWT Authentication Middleware
PSR-15 JWT authentication middleware with zero-config approach. Just add your JWT secret and you're ready to go!
Features
- ✅ Zero Configuration - Works out of the box with environment variables
- ✅ PSR-15 Compliant - Standard middleware interface
- ✅ Framework Agnostic - Works with any PSR-15 compatible framework
- ✅ Flexible Token Extraction - Bearer token (default) or custom header
- ✅ Multiple Algorithms - Supports HS256 (symmetric) and RS256 (asymmetric)
- ✅ Standard Claims Validation - Validates exp, nbf, iss, aud automatically
- ✅ Optional User Loading - Inject your own user loader
- ✅ Optional Scope Validation - Route-level permission checks
- ✅ Route-Specific Protection - Opt-in authentication per route
Installation
Quick Start
1. Set Environment Variable
2. Add to Your Pipeline
Mezzio:
Slim:
3. Protect Routes
Mezzio:
In Your Handler:
That's it! 🎉
Configuration
Environment Variables (Zero-Config)
| Variable | Default | Description |
|---|---|---|
JWT_SECRET |
- | Secret key for HS256 (required if using symmetric) |
JWT_PUBLIC_KEY_PATH |
- | Path to public key for RS256 (required if using asymmetric) |
JWT_ALGORITHM |
HS256 |
Algorithm: HS256 or RS256 |
JWT_ISSUER |
- | Expected iss claim (optional) |
JWT_AUDIENCE |
- | Expected aud claim (optional) |
JWT_HEADER_NAME |
Authorization |
Header to extract token from |
JWT_HEADER_PREFIX |
Bearer |
Token prefix (e.g., "Bearer ") |
Advanced Configuration (Optional)
If you need more control, create a configuration file:
Usage Examples
Protect Specific Routes
Scope/Permission Validation
In your token, include a scope claim:
Custom User Loading
Implement UserLoaderInterface to load user from database:
Register in container:
Now $request->getAttribute('user') contains your user object!
Generate Tokens (Separate from Middleware)
Request Attributes
After successful authentication, these attributes are added to the request:
| Attribute | Type | Description |
|---|---|---|
jwt_token |
Lcobucci\JWT\Token\Plain |
Full parsed token |
jwt_claims |
Lcobucci\JWT\Token\DataSet |
Token claims |
user |
object|null |
Loaded user (if user loader configured) |
Exceptions
All exceptions extend MethorZ\JwtAuthMiddleware\Exception\JwtAuthenticationException:
| Exception | When Thrown |
|---|---|
MissingTokenException |
No token in request |
InvalidTokenException |
Token is malformed |
ExpiredTokenException |
Token has expired |
InvalidSignatureException |
Signature verification failed |
InsufficientScopeException |
Required scope missing |
Recommendation: Use with methorz/http-problem-details to automatically format exceptions as RFC 7807 Problem Details responses.
Testing
Requirements
- PHP 8.2 or higher
- PSR-15 compatible framework
- lcobucci/jwt ^5.4
License
MIT License. See LICENSE for details.
Contributing
Contributions welcome! Please ensure:
- All tests pass
- Code follows PSR-12
- PHPStan level 9 passes
- Zero-config principle maintained
All versions of jwt-auth-middleware with dependencies
lcobucci/clock Version ^3.2
lcobucci/jwt Version ^5.4
psr/clock Version ^1.0
psr/container Version ^1.1|^2.0
psr/http-message Version ^1.1|^2.0
psr/http-server-handler Version ^1.0
psr/http-server-middleware Version ^1.0