Download the PHP
package waaseyaa/oidc without Composer
On this page you can find all versions of the php package
waaseyaa/oidc. It is possible to download/install
these versions without Composer. Possible dependencies are resolved
automatically.
Vendor waaseyaa Package oidc Short Description OpenID Connect issuer for Waaseyaa — ecosystem-wide single sign-on License
GPL-2.0-or-later
FAQ
After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.
Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.
In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories.
In this case some credentials are needed to access such packages.
Please use the auth.json textarea to insert credentials, if a package is coming from a private repository.
You can look here for more information.
Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
To use Composer is sometimes complicated. Especially for beginners.
Composer needs much resources. Sometimes they are not available on a simple webspace.
If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?
Informations about the package oidc
waaseyaa/oidc
OpenID Connect issuer for the Waaseyaa ecosystem.
This package provides the authorization-server primitives used by a dedicated IdP app to act as the single sign-on provider for every Waaseyaa app (Giiken, Minoo, OIATC, NorthOps, etc.). Consumer apps do not install this package — they federate to the IdP via waaseyaa/oauth-provider's GenericOidcProvider.
Scope
Authorization endpoint (/authorize)
Token endpoint (/token)
UserInfo endpoint (/userinfo)
Discovery (/.well-known/openid-configuration)
JWKS (/.well-known/jwks.json)
Revocation (/revoke)
RP-initiated logout (/end_session)
Signing-key storage + rotation
Non-goals (v1)
Multi-tenant realms
Dynamic client registration (RFC 7591)
SCIM provisioning
Federation chaining
Security: secrets at rest
OIDC secret persistence is rooted in WAASEYAA_APP_SECRET through distinct,
versioned HKDF-SHA-256 purposes:
RSA private keys use sodium secretbox with a fresh nonce and a strict
secretbox.hkdf-v1: envelope. Public-key material remains directly readable.
Opaque access and refresh tokens use separate secretbox encryption keys and
separate HMAC-SHA-256 lookup keys. Exact lookup uses the keyed lookup column;
the bearer value is returned only after its encrypted envelope authenticates.
Issuer signing uses the encrypted database repository unless file keys are
explicitly configured. Database key configuration or decryption errors are
propagated and do not select another provider.
Existing installations run bin/waaseyaa oidc:migrate-secrets --confirm in
maintenance mode after taking a trusted backup. The command converts signing
keys, access tokens, and refresh tokens in one transaction. Runtime readers
accept only authenticated envelopes; there is no ongoing plaintext read mode.
See docs/upgrade-notes/oidc-secrets-at-rest.md for the bounded procedure.
See ADR-006 for full context.
Status
Scaffold only. Implementation lands in follow-up PRs, TDD order per ADR-006 §7: discovery → JWKS → authorization code flow → token → userinfo → revocation → logout.
Composer command for our command line client (download client)This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free.Standard composer command
The package waaseyaa/oidc contains the following files
Loading the files please wait ...
Loading please wait ...
Before you can download the PHP files, the dependencies should be resolved. This can take some minutes. Please be patient.