PHP code example of webteractive / laravel-passwordless

1. Go to this page and download the library: Download webteractive/laravel-passwordless library. Choose the download type require.

2. Extract the ZIP file and open the index.php.

3. Add this code to the index.php.
    
        
<?php
require_once('vendor/autoload.php');

/* Start to develop here. Best regards https://php-download.com/ */

    

webteractive / laravel-passwordless example snippets


   'google' => [
       'client_id'     => env('GOOGLE_CLIENT_ID'),
       'client_secret' => env('GOOGLE_CLIENT_SECRET'),
       'redirect'      => env('GOOGLE_REDIRECT_URI'),
   ],
   

   'social' => [
       'providers' => [
           'google',
           'github' => ['scopes' => ['read:user']],
       ],
       'auto_register' => true,
   ],
   

use Webteractive\Passwordless\Facades\Passwordless;

Passwordless::resolveSocialUserUsing(function (string $provider, $oauth, $container) {
    // return an app user, or null to deny
    return User::firstOrCreate(['email' => $oauth->getEmail()], ['name' => $oauth->getName()]);
});

// config/passwordless.php
'strategies' => [
    'magic_code' => [
        'enabled' => true,
        'ttl' => 15 * 60,        // shared TTL for BOTH the link and the code
        'same_browser' => true,  // enforced on the LINK path only
        'code' => ['length' => 6],
    ],
],

use Webteractive\Passwordless\Facades\Passwordless;

Passwordless::magicCode()->send('[email protected]');

// What the package checks, in effect:
class_exists(Laravel\Fortify\Fortify::class)
    && in_array(TwoFactorAuthenticatable::class, class_uses_recursive($user))
    && $user->hasEnabledTwoFactorAuthentication()

if (Passwordless::twoFactor()->ctor()->challenge($user, $request, $remember);
}

Fortify::confirmPasswordsUsing(function ($user, $password) {
    // Users who DO have a password keep the normal path.
    if ($password && $user->getAuthPassword() && Auth::guard(config('fortify.guard'))->validate([
        Fortify::username() => $user->{Fortify::username()},
        'password' => $password,
    ])) {
        return true;
    }

    return Passwordless::confirmation()->verify($user, (string) $password);
});

'confirmation' => [
    'enabled' => true,   // ,

'remember' => [
    'enabled' => true,   // false forces remember off everywhere, whatever clients send
],

'dev_login' => [
    'enabled'      => false,      // deliberately a literal, not env() — see below
    'environments' => ['local'],
    'two_factor'   => false,      // dev logins skip the 2FA challenge by default
    'limit'        => 50,
],

'domains' => [
    'allowed' => ['acme.com'],
    'enforce' => [
        'passwordless' => ['login' => false, 'register' => true],
        'social'       => ['login' => true,  'register' => true],
    ],
],

return [
    'user_model' => App\Models\User::class,
    'user_email_column' => 'email',
    'auto_create_users' => false,

    'guard' => 'web',
    'route_prefix' => 'auth',
    'redirect' => '/',          // where the UI kit sends users after login
    'api_mode' => false,        // return a token instead of a session login

    'resend_cooldown' => 30,
    'lockout' => ['max_attempts' => 5, 'window' => 15 * 60],

    'branding' => [
        'app_name' => env('APP_NAME'),
        'support_email' => null,
    ],

    'strategies' => [
        'magic_link' => ['enabled' => true, 'ttl' => 15 * 60, 'same_browser' => true],
        'login_code' => ['enabled' => true, 'length' => 6, 'ttl' => 10 * 60, 'channel' => 'mail'],
    ],

    'social' => [
        'providers' => ['google', 'github' => ['scopes' => ['read:user']]],
        'auto_register' => true,
        'trusted_providers' => ['google', 'github', 'apple', /* … */], // treated as verified-email
    ],

    'domains' => [
        'allowed' => [],          // empty = unrestricted
        'enforce' => [
            'passwordless' => ['login' => false, 'register' => true],
            'social'       => ['login' => false, 'register' => true],
        ],
    ],
];

use Webteractive\Passwordless\Facades\Passwordless;

Passwordless::gateUsing(fn ($user, $context) =>
    $user->is_active
        ? Passwordless::allow()
        : Passwordless::deny('account disabled')
);

use Webteractive\Passwordless\Support\AuthEvent;

Passwordless::recordUsing(fn (AuthEvent $event) => AuditLog::write($event));

use Webteractive\Passwordless\Facades\Passwordless;

Passwordless::redirectUsing(fn ($user, $request) =>
    $user->is_admin ? '/admin' : '/dashboard'
);

Passwordless::twoFactor()->>challenge($user, $request, $remember); // Response — hands off to Fortify

Passwordless::confirmation()->send($user);                     // emails a confirmation code
Passwordless::confirmation()->verify($user, $code);            // bool — Fortify-callback shaped

use Webteractive\Passwordless\Contracts\LoginCodeChannel;

class SmsChannel implements LoginCodeChannel
{
    public function send(mixed $user, string $email, string $code, array $context = []): void
    {
        // Twilio, Vonage, etc.
    }
}

// Register it in a service provider:
$this->app->bind('passwordless.login_code_channels.sms', SmsChannel::class);

// config/passwordless.php
'strategies' => [
    'login_code' => ['channel' => 'sms'],
],

use Webteractive\Passwordless\Facades\Passwordless;

it('sends a magic link', function () {
    $fake = Passwordless::fake();

    Passwordless::magicLink()->send('[email protected]');

    $fake->assertLinkSent('[email protected]');
});

Schedule::command('passwordless:prune')->hourly();
bash
php artisan vendor:publish --tag="passwordless-migrations"
php artisan migrate
bash
php artisan vendor:publish --tag="passwordless-config"
bash
php artisan vendor:publish --tag="passwordless-translations"
php artisan vendor:publish --tag="passwordless-views"

POST /auth/magic-code            { email }                 -> 202 (always)
GET  /auth/magic-code/{token}    (signed link click)       -> sign in + redirect
POST /auth/magic-code/verify     { email, code }           -> 204 (sign in)
bash
# Standalone (greenfield)
php artisan vendor:publish --tag=passwordless-ui-livewire
php artisan vendor:publish --tag=passwordless-ui-react
php artisan vendor:publish --tag=passwordless-ui-vue

# Integrated with an official starter kit
php artisan vendor:publish --tag=passwordless-ui-livewire-embed
php artisan vendor:publish --tag=passwordless-ui-react-embed
php artisan vendor:publish --tag=passwordless-ui-vue-embed
bash
php artisan passwordless:prune   # delete expired / consumed challenges