Download the PHP package mortezamasumi/fb-auth without Composer
On this page you can find all versions of the php package mortezamasumi/fb-auth. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download mortezamasumi/fb-auth
More information about mortezamasumi/fb-auth
Files in mortezamasumi/fb-auth
Package fb-auth
Short Description Filament authentication with mobile, code, username, and magic-link flows
License MIT
Homepage https://github.com/mortezamasumi/fb-auth
Informations about the package fb-auth
FB Auth — Filament Authentication
A Filament v5 plugin that provides configurable authentication flows for your Laravel admin panel: magic link, email code, mobile SMS code, and username/password. It ships custom login, registration, email verification, and password-reset pages — with rate-limited, OTP-based resend actions and bilingual notifications.
Features
- Four auth flows — switch with a single config key:
link(magic link),code(email code),mobile(SMS code via fb-sms), anduser(username/password) - OTP login & registration — dedicated pages with a resendable, expiring code for
codeandmobileflows - Code-based password reset — request, resend, and reset flows built on the same OTP mechanism
- Account verification by code or SMS — replaces Filament's signed-email-link verification with an OTP prompt page for
codeandmobileflows - SMS delivery — mobile codes are sent through the configured fb-sms gateway
- Rate limiting — every send/verify action is throttled to prevent abuse
- Localized UI — Persian and English translations shipped out of the box
Installation
Publish the config file:
Optionally publish the views:
Configuration
auth_type—link(default),code,mobile, oruserotp_digits— length of the generated verification code (default4)otp_expiration— code lifetime in seconds (default120)
Usage
Register the plugin in a panel
Choose an auth flow
Set AUTH_TYPE in your .env:
| Value | Flow | Login / register | Reset password |
|---|---|---|---|
link |
Magic link | Filament's built-in pages | Filament's built-in pages |
code |
Email code | OTP page (code sent by email) | OTP-based reset pages |
mobile |
Mobile SMS code | OTP page (code sent by SMS) | OTP-based reset pages |
user |
Username / password | Filament's built-in pages | disabled |
Generate and send codes
Account verification
Filament only enforces verification on a panel that calls ->emailVerification() and when the user model implements Illuminate\Contracts\Auth\MustVerifyEmail. Once both are in place, the plugin swaps the stock verification pages for its own, matching the selected flow:
AUTH_TYPE |
Verification prompt | Code delivery | Resend action |
|---|---|---|---|
link |
Filament's built-in signed-link page | Laravel's default verify email | stock resend mail |
code |
OTP input page | VerifyCodeNotification (email with the code inline) |
re-sends the email code |
mobile |
OTP input page | VerifyMobileNotification (SMS via fb-sms) |
re-sends the SMS code |
user |
verification disabled entirely (->emailVerification(null)) |
— | — |
Panel wiring
Enable the features you want; the plugin replaces their pages automatically:
Multi-panel apps: every panel that enables
->emailVerification()should also registerFbAuthPlugin, otherwise unverified users are sent to Filament's stock "click the link in your email" page instead of the OTP prompt.
Model requirements
- Implement
MustVerifyEmail. - Use the
Notifiabletrait — codes are delivered through the notification system. - For the
mobileflow: amobilecolumn on the user, fb-sms installed with an operator configured (config('fb-sms.operator')), andAUTH_TYPE=mobilein.env. The destination defaults to$user->mobile; customize it withrouteNotificationFor('sms')on the model if needed. - The registration page adapts per flow:
mobileshows first name / last name / mobile / password,codeandlinkshow first name / last name / email / password,userasks for username instead of email.
How it works
- On registration (or via the Resend code action on the prompt page),
FbAuth::createCode($user)generates anotp_digits-long code and caches it underotp-{identifier}forotp_expirationseconds. The identifier is the user'smobilefor themobileflow,emailotherwise. - The user submits the code on the verification prompt. A correct, unexpired call marks the account verified (
markEmailAsVerified()) and fires the standardIlluminate\Auth\Events\Verifiedevent; a wrong or expired code fails validation with a bilingual message and offers resend. - Every submit/resend is rate limited (2 attempts per minute). After verification the user is redirected back to the panel URL.
- If you use fb-user's
Usermodel, changing the identifier attribute (mobileoremail) resetsemail_verified_at, requiring verification again.
Customizing the pages
Pass your own page classes to the panel methods as usual — the plugin only fills in defaults for anything you have not overridden:
The notifications themselves can be swapped by binding VerifyCodeNotification / VerifyMobileNotification in the container or by publishing and editing the package translations (fb-auth::fb-auth.*).
Support policy
| PHP | Laravel | Filament |
|---|---|---|
| 8.3 | 12 | 5.x |
Testing
Contributing
Please see CONTRIBUTING for details.
Security
If you discover a security vulnerability, please review our security policy on how to report it.
Changelog
Please see CHANGELOG for recent changes.
License
The MIT License (MIT). See LICENSE.md for details.
All versions of fb-auth with dependencies
ariaieboy/filament-jalali Version ^3.0
filament/filament Version ^5.0
mortezamasumi/fb-essentials Version ^5.0
mortezamasumi/fb-sms Version ^5.0
spatie/laravel-package-tools Version ^1.0