Download the PHP package newlandpe/oauth2-xauthconnect without Composer
On this page you can find all versions of the php package newlandpe/oauth2-xauthconnect. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download newlandpe/oauth2-xauthconnect
More information about newlandpe/oauth2-xauthconnect
Files in newlandpe/oauth2-xauthconnect
Package oauth2-xauthconnect
Short Description XAuthConnect provider for The PHP League OAuth2-Client
License LicenseRef-CSSM-Unlimited-2.0
Informations about the package oauth2-xauthconnect
XAuthConnect Provider for The PHP League OAuth 2.0 Client
This package provides an OAuth 2.0 client provider for integrating with an XAuthConnect authorization server. It is built to work with the popular league/oauth2-client package.
This provider allows you to easily implement the "Login with XAuthConnect" functionality in any PHP application that uses league/oauth2-client.
Features
- OIDC Discovery: Automatically configure endpoints from a single
issuerURL. - Implements the standard Authorization Code Grant flow.
- Supports PKCE (Proof Key for Code Exchange) for enhanced security.
- Provides helper methods for XAuthConnect-specific features:
- Token Introspection (
introspectToken) - Token Revocation (
revokeToken)
- Token Introspection (
- Fully compliant with the
league/oauth2-clientAbstractProvider. - Exposes user data (
ID,Nickname) through aResourceOwnerobject.
Installation
Install the package via Composer:
This package now requires guzzlehttp/guzzle v7.0 or greater.
Installing from a local path (for development)
If you're developing this library locally or need to use it as a path repository:
- Place this library in a directory within your project (e.g.,
oauth_libs/oauth2-xauthconnect). -
Add the following to your main
composer.jsonfile: - Run
composer updateto install the dependencies.
Usage
Follow these steps to integrate XAuthConnect into your application.
1. Initialization
You can initialize the provider in two ways.
Method 1: OIDC Discovery (Recommended)
Provide the issuer URL of your XAuthConnect server. The provider will automatically discover all the required endpoint URLs.
[!IMPORTANT] The
issuerURL must be publicly accessible and resolvable from the environment where your application is running for OIDC discovery to succeed. If the issuer is not accessible, you must use Method 2 for manual configuration.
Method 2: Manual Configuration
If your OIDC issuer is not publicly accessible, or if you need to specify or override specific endpoint URLs manually, you can do so by providing them in the constructor options. This method is also useful for overriding a specific endpoint URL discovered via the issuer.
The following options are available for manual configuration:
baseAuthorizationUrlbaseAccessTokenUrlresourceOwnerDetailsUrlintrospectUrlrevokeUrl
For example, if the discovery document provides a wrong token_endpoint, you can override it:
2. Authorization
Redirect the user to the XAuthConnect server to authorize your application.
3. Getting an Access Token
After the user authorizes, they will be redirected back to your redirectUri with a code. Use this code to get an access token.
4. Getting Resource Owner Details
With the access token, you can now fetch the user's profile information.
Extra Features
This provider includes methods for XAuthConnect-specific endpoints.
Introspecting a Token
You can check if a token is active and view its metadata.
Revoking a Token
You can invalidate an access or refresh token on the server.
Contributing
Contributions are welcome and appreciated! Here's how you can contribute:
- Fork the project on GitHub.
- Create your feature branch (
git checkout -b feature/AmazingFeature). - Commit your changes (
git commit -m 'Add some AmazingFeature'). - Push to the branch (
git push origin feature/AmazingFeature). - Open a Pull Request.
Please make sure to update tests as appropriate and adhere to the existing coding style.
License
This library is licensed under the CSSM Unlimited License v2.0 (CSSM-ULv2). See the LICENSE file for details.
All versions of oauth2-xauthconnect with dependencies
league/oauth2-client Version ^2.0
guzzlehttp/guzzle Version ^7.0
firebase/php-jwt Version ^6.0