Skip to content
This repository was archived by the owner on Jan 25, 2026. It is now read-only.

feat: Complete AuthKit implementation with multi-tenancy support - #4

Merged
jvjvjv merged 1 commit into
mainfrom
claude/import-authkit-pr-commits-018375xARTLnZ9yzSYicHtJ9
Nov 17, 2025
Merged

jvjvjv merged 1 commit into
mainfrom
claude/import-authkit-pr-commits-018375xARTLnZ9yzSYicHtJ9

Conversation

@jvjvjv

@jvjvjv jvjvjv commented Nov 17, 2025

Copy link
Copy Markdown
Contributor

This commit encompasses the full implementation of BSPDX AuthKit, a comprehensive Laravel authentication package with the following features:

  • Standard authentication via Laravel Fortify
  • Role-based access control using Spatie Laravel Permission
  • TOTP 2FA with Google Authenticator support
  • WebAuthn/Passkey authentication
  • API support with Laravel Sanctum
  • Multi-tenancy database support
  • Complete testing suite with feature and unit tests
  • Blade components for authentication UI
  • Database migrations and seeders
  • Middleware for role, permission, and 2FA enforcement

This squashed commit includes all work from PR #3:

  • Initial AuthKit package creation
  • Middleware test fixes
  • User model configuration
  • HasPasskeys namespace corrections
  • Spatie service provider registration
  • General updates and improvements
  • Multi-tenancy database integration

Co-authored-by: Claude

This commit encompasses the full implementation of BSPDX AuthKit, a comprehensive
Laravel authentication package with the following features:

- Standard authentication via Laravel Fortify
- Role-based access control using Spatie Laravel Permission
- TOTP 2FA with Google Authenticator support
- WebAuthn/Passkey authentication
- API support with Laravel Sanctum
- Multi-tenancy database support
- Complete testing suite with feature and unit tests
- Blade components for authentication UI
- Database migrations and seeders
- Middleware for role, permission, and 2FA enforcement

This squashed commit includes all work from PR #3:
- Initial AuthKit package creation
- Middleware test fixes
- User model configuration
- HasPasskeys namespace corrections
- Spatie service provider registration
- General updates and improvements
- Multi-tenancy database integration

Co-authored-by: Jason <jvjvjv@users.noreply.github.com>
Co-authored-by: Jason Vertucio <m.jasonvertucio@gmail.com>
Co-authored-by: Claude
Copilot AI review requested due to automatic review settings November 17, 2025 02:44
@jvjvjv
jvjvjv merged commit 778ef11 into main Nov 17, 2025
7 checks passed
@jvjvjv
jvjvjv deleted the claude/import-authkit-pr-commits-018375xARTLnZ9yzSYicHtJ9 branch November 17, 2025 02:46

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR implements a comprehensive authentication package called BSPDX AuthKit for Laravel 12, providing a complete solution for authentication, authorization, and user management with modern security features.

Purpose: Create a reusable Laravel package that combines standard authentication (Laravel Fortify), role-based access control (Spatie Laravel Permission), TOTP 2FA, WebAuthn/Passkey authentication (Spatie Laravel Passkeys), API support (Laravel Sanctum), and optional multi-tenancy database support.

Key Changes:

  • Complete authentication package implementation with traits, middleware, controllers, and Blade components
  • Role-based access control with super admin support and permission management
  • Multi-factor authentication support including TOTP 2FA and Passkey authentication
  • Comprehensive test coverage with unit and feature tests
  • Package configuration, migrations, seeders, and documentation

Reviewed Changes

Copilot reviewed 31 out of 33 changed files in this pull request and generated 4 comments.

Show a summary per file
File Description
src/Traits/HasAuthKit.php Core trait combining authentication functionalities from Fortify, Sanctum, Spatie Permission, and Passkeys
src/Http/Controllers/TwoFactorAuthController.php TOTP 2FA management including enable, confirm, disable, and recovery code operations
src/Http/Controllers/RolePermissionController.php RBAC management API for roles, permissions, and user assignments
src/Http/Controllers/PasskeyAuthController.php WebAuthn/Passkey registration, authentication, and management
src/Http/Middleware/*.php Middleware for role, permission, and 2FA enforcement
src/View/Components/*.php Reusable Blade components for login, register, 2FA challenge, and passkey forms
src/AuthKitServiceProvider.php Service provider for package registration, asset publishing, and middleware aliases
resources/views/components/*.blade.php Blade component templates with embedded JavaScript for passkey functionality
config/authkit.php Comprehensive package configuration for features, RBAC, passkeys, 2FA, and multi-tenancy
database/migrations/*.php Migration adding 2FA columns and tenant_id to users table
database/seeders/AuthKitSeeder.php Seeder creating default roles, permissions, and demo users
tests/Unit/HasAuthKitTraitTest.php Unit tests for HasAuthKit trait methods
tests/Feature/AuthKitTest.php Feature tests for authentication flows and RBAC functionality
composer.json Package dependencies updated to include Spatie packages and remove Inertia/Ziggy/Tinker
app/Models/User.php User model updated with HasAuthKit trait and HasPasskeys interface
bootstrap/providers.php Service providers registered for AuthKit and dependencies
README.md Comprehensive documentation with installation, configuration, and usage examples
docs/https-setup.md Detailed HTTPS setup guide for local passkey development
routes/*.example.php Example web and API routes for AuthKit features
package-lock.json Frontend dependencies updated to Vite 7, Tailwind 4, and Axios 1.11

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread README.md
[![License](https://img.shields.io/packagist/l/bspdx/authkit.svg?style=flat-square)](https://packagist.org/packages/bspdx/authkit)

## Features
A comprehensive, production-ready authentication package for Laravel 12. AuthKin combines the power of Laravel Fortify, Sanctum, Spatie Laravel Permission, and Spatie Laravel Passkeys to provide a full-featured auth system with:

Copilot AI Nov 17, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The package name in README.md on line 7 contains a typo: "AuthKin" should be "AuthKit".

Suggested change
A comprehensive, production-ready authentication package for Laravel 12. AuthKin combines the power of Laravel Fortify, Sanctum, Spatie Laravel Permission, and Spatie Laravel Passkeys to provide a full-featured auth system with:
A comprehensive, production-ready authentication package for Laravel 12. AuthKit combines the power of Laravel Fortify, Sanctum, Spatie Laravel Permission, and Spatie Laravel Passkeys to provide a full-featured auth system with:

Copilot uses AI. Check for mistakes.
Comment thread app/Models/User.php
use Spatie\LaravelPasskeys\Models\Concerns\HasPasskeys;

class User extends Authenticatable
class User extends Authenticatable implements HasPasskeys

Copilot AI Nov 17, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The User model implements HasPasskeys interface but should implement HasPasskeysInterface. The Spatie Laravel Passkeys package uses Models\Concerns\InteractsWithPasskeys as a trait and doesn't define an interface with this name.

Copilot uses AI. Check for mistakes.
*/
protected function getRecoveryCodes($user): array
{
return json_decode(decrypt($user->two_factor_recovery_codes), true);

Copilot AI Nov 17, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing error handling for potential null or invalid values when decrypting two_factor_recovery_codes. If the value is null or the decryption fails, this will throw an exception. Consider adding null checks and error handling.

Suggested change
return json_decode(decrypt($user->two_factor_recovery_codes), true);
if (empty($user->two_factor_recovery_codes)) {
return [];
}
try {
return json_decode(decrypt($user->two_factor_recovery_codes), true) ?? [];
} catch (\Exception $e) {
// Optionally log the error: \Log::error($e);
return [];
}

Copilot uses AI. Check for mistakes.
Comment thread src/Traits/HasAuthKit.php
Comment on lines +8 to +15
use Spatie\LaravelPasskeys\Models\Concerns\InteractsWithPasskeys;

trait HasAuthKit
{
use HasApiTokens;
use TwoFactorAuthenticatable;
use HasRoles;
use InteractsWithPasskeys;

Copilot AI Nov 17, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The HasPasskeys interface is being used incorrectly. According to the Spatie Laravel Passkeys documentation, InteractsWithPasskeys is a trait, not an interface. The User model should only use the trait, not implement an interface.

Copilot uses AI. Check for mistakes.
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants