Download the PHP package mydaniel/laravel-paseto without Composer
On this page you can find all versions of the php package mydaniel/laravel-paseto. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Informations about the package laravel-paseto
Laravel Paseto
This package provides a PASETO (Platform-Agnostic Security Tokens) authentication guard for Laravel. It offers a modern, secure, and easy-to-use alternative to JWT (JSON Web Tokens).
Paseto tokens are encrypted and authenticated, providing better security guarantees than JWT out of the box.
Features
- ✅ Secure, stateless authentication for your Laravel applications.
- ✅ PASETO v4 Local support (symmetric key authenticated encryption).
- ✅ Easy to configure and use.
- ✅ Token blacklist functionality to invalidate tokens upon logout.
- ✅ An artisan command to generate a secure secret key.
- ✅ Fully customizable through configuration and contracts.
Installation
You can install the package via composer:
Configuration
-
Publish the configuration file:
This will create a
config/paseto.phpfile in your project. You can customize token expiration, issuer, audience, and other claims here. -
Generate a Secret Key:
Run the following artisan command to generate a secure, 32-byte hex-encoded key. The command will automatically add it to your
.envfile.This will add a line like this to your
.envfile: -
Configure the Auth Guard:
Open your
config/auth.phpfile and make the following changes:
Usage
1. Preparing Your User Model
Add the MyDaniel\Paseto\Contracts\PasetoSubject contract and the MyDaniel\Paseto\Traits\HasPaseto trait to your User model.
The PasetoSubject contract ensures your model has the necessary methods for generating token claims. The HasPaseto trait provides a ready-to-use implementation for these methods.
2. Generating a Token
After authenticating a user (e.g., in a login controller), you can generate a token for them.
3. Protecting Routes
Use the auth:api middleware in your routes/api.php file to protect routes that require authentication.
Clients should send the token in the Authorization header as a Bearer token:
4. Logging Out (Invalidating a Token)
To invalidate a token, you can use the logout method from the Auth facade. This will add the token's unique identifier (jti) to the blacklist for its remaining lifetime.
Note: The blacklist feature requires a cache driver. By default, it uses your application's default cache driver. You can specify a different cache store in config/paseto.php.
Customizing Token Claims
You can add custom claims to your tokens by implementing the getJwtCustomClaims method in your User model.
Contributing
Contributions are welcome! Please feel free to submit a pull request on GitHub.
License
The MIT License (MIT). Please see License File for more information.
All versions of laravel-paseto with dependencies
illuminate/auth Version ^9.0|^10.0|^11.0|^12.0
illuminate/contracts Version ^9.0|^10.0|^11.0|^12.0
illuminate/support Version ^9.0|^10.0|^11.0|^12.0
paragonie/paseto Version ^v3.0