feat: Complete AuthKit implementation with multi-tenancy support - #4
Conversation
This commit encompasses the full implementation of BSPDX AuthKit, a comprehensive Laravel authentication package with the following features: - Standard authentication via Laravel Fortify - Role-based access control using Spatie Laravel Permission - TOTP 2FA with Google Authenticator support - WebAuthn/Passkey authentication - API support with Laravel Sanctum - Multi-tenancy database support - Complete testing suite with feature and unit tests - Blade components for authentication UI - Database migrations and seeders - Middleware for role, permission, and 2FA enforcement This squashed commit includes all work from PR #3: - Initial AuthKit package creation - Middleware test fixes - User model configuration - HasPasskeys namespace corrections - Spatie service provider registration - General updates and improvements - Multi-tenancy database integration Co-authored-by: Jason <jvjvjv@users.noreply.github.com> Co-authored-by: Jason Vertucio <m.jasonvertucio@gmail.com> Co-authored-by: Claude
There was a problem hiding this comment.
Pull Request Overview
This PR implements a comprehensive authentication package called BSPDX AuthKit for Laravel 12, providing a complete solution for authentication, authorization, and user management with modern security features.
Purpose: Create a reusable Laravel package that combines standard authentication (Laravel Fortify), role-based access control (Spatie Laravel Permission), TOTP 2FA, WebAuthn/Passkey authentication (Spatie Laravel Passkeys), API support (Laravel Sanctum), and optional multi-tenancy database support.
Key Changes:
- Complete authentication package implementation with traits, middleware, controllers, and Blade components
- Role-based access control with super admin support and permission management
- Multi-factor authentication support including TOTP 2FA and Passkey authentication
- Comprehensive test coverage with unit and feature tests
- Package configuration, migrations, seeders, and documentation
Reviewed Changes
Copilot reviewed 31 out of 33 changed files in this pull request and generated 4 comments.
Show a summary per file
| File | Description |
|---|---|
src/Traits/HasAuthKit.php |
Core trait combining authentication functionalities from Fortify, Sanctum, Spatie Permission, and Passkeys |
src/Http/Controllers/TwoFactorAuthController.php |
TOTP 2FA management including enable, confirm, disable, and recovery code operations |
src/Http/Controllers/RolePermissionController.php |
RBAC management API for roles, permissions, and user assignments |
src/Http/Controllers/PasskeyAuthController.php |
WebAuthn/Passkey registration, authentication, and management |
src/Http/Middleware/*.php |
Middleware for role, permission, and 2FA enforcement |
src/View/Components/*.php |
Reusable Blade components for login, register, 2FA challenge, and passkey forms |
src/AuthKitServiceProvider.php |
Service provider for package registration, asset publishing, and middleware aliases |
resources/views/components/*.blade.php |
Blade component templates with embedded JavaScript for passkey functionality |
config/authkit.php |
Comprehensive package configuration for features, RBAC, passkeys, 2FA, and multi-tenancy |
database/migrations/*.php |
Migration adding 2FA columns and tenant_id to users table |
database/seeders/AuthKitSeeder.php |
Seeder creating default roles, permissions, and demo users |
tests/Unit/HasAuthKitTraitTest.php |
Unit tests for HasAuthKit trait methods |
tests/Feature/AuthKitTest.php |
Feature tests for authentication flows and RBAC functionality |
composer.json |
Package dependencies updated to include Spatie packages and remove Inertia/Ziggy/Tinker |
app/Models/User.php |
User model updated with HasAuthKit trait and HasPasskeys interface |
bootstrap/providers.php |
Service providers registered for AuthKit and dependencies |
README.md |
Comprehensive documentation with installation, configuration, and usage examples |
docs/https-setup.md |
Detailed HTTPS setup guide for local passkey development |
routes/*.example.php |
Example web and API routes for AuthKit features |
package-lock.json |
Frontend dependencies updated to Vite 7, Tailwind 4, and Axios 1.11 |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| [](https://packagist.org/packages/bspdx/authkit) | ||
|
|
||
| ## Features | ||
| A comprehensive, production-ready authentication package for Laravel 12. AuthKin combines the power of Laravel Fortify, Sanctum, Spatie Laravel Permission, and Spatie Laravel Passkeys to provide a full-featured auth system with: |
There was a problem hiding this comment.
The package name in README.md on line 7 contains a typo: "AuthKin" should be "AuthKit".
| A comprehensive, production-ready authentication package for Laravel 12. AuthKin combines the power of Laravel Fortify, Sanctum, Spatie Laravel Permission, and Spatie Laravel Passkeys to provide a full-featured auth system with: | |
| A comprehensive, production-ready authentication package for Laravel 12. AuthKit combines the power of Laravel Fortify, Sanctum, Spatie Laravel Permission, and Spatie Laravel Passkeys to provide a full-featured auth system with: |
| use Spatie\LaravelPasskeys\Models\Concerns\HasPasskeys; | ||
|
|
||
| class User extends Authenticatable | ||
| class User extends Authenticatable implements HasPasskeys |
There was a problem hiding this comment.
The User model implements HasPasskeys interface but should implement HasPasskeysInterface. The Spatie Laravel Passkeys package uses Models\Concerns\InteractsWithPasskeys as a trait and doesn't define an interface with this name.
| */ | ||
| protected function getRecoveryCodes($user): array | ||
| { | ||
| return json_decode(decrypt($user->two_factor_recovery_codes), true); |
There was a problem hiding this comment.
Missing error handling for potential null or invalid values when decrypting two_factor_recovery_codes. If the value is null or the decryption fails, this will throw an exception. Consider adding null checks and error handling.
| return json_decode(decrypt($user->two_factor_recovery_codes), true); | |
| if (empty($user->two_factor_recovery_codes)) { | |
| return []; | |
| } | |
| try { | |
| return json_decode(decrypt($user->two_factor_recovery_codes), true) ?? []; | |
| } catch (\Exception $e) { | |
| // Optionally log the error: \Log::error($e); | |
| return []; | |
| } |
| use Spatie\LaravelPasskeys\Models\Concerns\InteractsWithPasskeys; | ||
|
|
||
| trait HasAuthKit | ||
| { | ||
| use HasApiTokens; | ||
| use TwoFactorAuthenticatable; | ||
| use HasRoles; | ||
| use InteractsWithPasskeys; |
There was a problem hiding this comment.
The HasPasskeys interface is being used incorrectly. According to the Spatie Laravel Passkeys documentation, InteractsWithPasskeys is a trait, not an interface. The User model should only use the trait, not implement an interface.
This commit encompasses the full implementation of BSPDX AuthKit, a comprehensive Laravel authentication package with the following features:
This squashed commit includes all work from PR #3:
Co-authored-by: Claude