Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -6,3 +6,4 @@
/.vscode
laravel-fortify-auth-packages.md
.DS_Store
/composer.lock
44 changes: 22 additions & 22 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# Laravel Auth Kit
# laranail/authkit

Headless authentication for Laravel 13+. No views, routes, or controllers.

Expand All @@ -17,8 +17,8 @@ PHP 8.4+ / Laravel 13.x
## Installation

```bash
composer require laranail/auth-kit
php artisan vendor:publish --tag=auth-kit-config
composer require laranail/authkit
php artisan vendor:publish --tag=laranail::authkit-config
```

For a ready-made Blade UI, install `laranail/auth-preset` instead.
Expand All @@ -43,24 +43,24 @@ For a ready-made Blade UI, install `laranail/auth-preset` instead.
`.env`:

```env
AUTH_KIT_GUARD=web
AUTH_KIT_RATE_LIMIT_MAX_ATTEMPTS=5
AUTH_KIT_RATE_LIMIT_DECAY_MINUTES=1
AUTHKIT_GUARD=web
AUTHKIT_RATE_LIMIT_MAX_ATTEMPTS=5
AUTHKIT_RATE_LIMIT_DECAY_MINUTES=1

AUTH_KIT_GOOGLE_CLIENT_ID=
AUTH_KIT_GOOGLE_CLIENT_SECRET=
AUTH_KIT_GOOGLE_REDIRECT=${APP_URL}/auth/google/callback
AUTHKIT_GOOGLE_CLIENT_ID=
AUTHKIT_GOOGLE_CLIENT_SECRET=
AUTHKIT_GOOGLE_REDIRECT=${APP_URL}/auth/google/callback
```

`config/auth-kit.php`:
`config/laranail/authkit.php`:

```php
return [
'guard' => env('AUTH_KIT_GUARD', 'web'),
'guard' => env('AUTHKIT_GUARD', 'web'),

'rate_limit' => [
'max_attempts' => (int) env('AUTH_KIT_RATE_LIMIT_MAX_ATTEMPTS', 5),
'decay_minutes' => (int) env('AUTH_KIT_RATE_LIMIT_DECAY_MINUTES', 1),
'max_attempts' => (int) env('AUTHKIT_RATE_LIMIT_MAX_ATTEMPTS', 5),
'decay_minutes' => (int) env('AUTHKIT_RATE_LIMIT_DECAY_MINUTES', 1),
],

'fortify' => [
Expand All @@ -70,32 +70,32 @@ return [

'social' => [
'google' => [
'client_id' => env('AUTH_KIT_GOOGLE_CLIENT_ID'),
'client_secret' => env('AUTH_KIT_GOOGLE_CLIENT_SECRET'),
'redirect' => env('AUTH_KIT_GOOGLE_REDIRECT'),
'client_id' => env('AUTHKIT_GOOGLE_CLIENT_ID'),
'client_secret' => env('AUTHKIT_GOOGLE_CLIENT_SECRET'),
'redirect' => env('AUTHKIT_GOOGLE_REDIRECT'),
'scopes' => ['openid', 'profile', 'email'],
],
// facebook, twitter, linkedin, paypal ...
],
];
```

Remove `passkeys` from `auth-kit.fortify.features` to disable Fortify's passkey routes. Auth Kit only enables and configures Fortify; passkey ceremonies, responses, and persistence remain provided by Fortify and `laravel/passkeys`.
Remove `passkeys` from `laranail.authkit.fortify.features` to disable Fortify's passkey routes. Auth Kit only enables and configures Fortify; passkey ceremonies, responses, and persistence remain provided by Fortify and `laravel/passkeys`.

### Security defaults

- Two-factor authentication is not enabled by default. MFA is still work in progress.
- Social sign-in only provisions or auto-links accounts when Google, LinkedIn, or PayPal supplies a trusted `email_verified` claim. Facebook and X identities can still be linked by an authenticated user, but cannot establish trust through an email-verification claim.
- Before production, configure HTTPS, secure session cookies, a working mail transport, and Turnstile keys when bot protection is enabled.
- PayPal uses sandbox mode by default. Set `AUTH_KIT_PAYPAL_SANDBOX_MODE=false` with production PayPal credentials before enabling it in production.
- PayPal uses sandbox mode by default. Set `AUTHKIT_PAYPAL_SANDBOX_MODE=false` with production PayPal credentials before enabling it in production.

## Passkeys

Passkey support uses Fortify's native integration with `laravel/passkeys`. It is stateful and requires the consuming application's authenticatable model to implement Fortify's `PasskeyUser` contract and use Auth Kit's morph-aware `PasskeyAuthenticatable` trait:

```php
use Laravel\Fortify\Contracts\PasskeyUser;
use Simtabi\Laranail\Auth\PasskeyAuthenticatable;
use Simtabi\Laranail\AuthKit\PasskeyAuthenticatable;

class User extends Authenticatable implements PasskeyUser
{
Expand All @@ -108,7 +108,7 @@ The published migration stores ownership in `passkeyable_type` and `passkeyable_
Publish Auth Kit's passkeys migration in the consuming application and run it:

```bash
php artisan vendor:publish --tag=auth-kit-passkey-migrations
php artisan vendor:publish --tag=laranail::authkit-passkey-migrations
php artisan migrate
```

Expand Down Expand Up @@ -206,7 +206,7 @@ Extend these to wire up your own routes. JSON responses are handled automaticall
Add to your `User` model:

```php
use Simtabi\Laranail\Auth\Models\Social;
use Simtabi\Laranail\AuthKit\Models\Social;
use Illuminate\Database\Eloquent\Relations\MorphMany;

public function socials(): MorphMany
Expand All @@ -218,7 +218,7 @@ public function socials(): MorphMany
Publish the migration:

```bash
php artisan vendor:publish --tag=auth-kit-social-migrations
php artisan vendor:publish --tag=laranail::authkit-social-migrations
```

## Usage
Expand Down
23 changes: 17 additions & 6 deletions composer.json
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
{
"$schema": "https://getcomposer.org/schema.json",
"name": "laranail/auth-kit",
"name": "laranail/authkit",
"type": "library",
"description": "A publish-first Laravel authentication scaffolding package.",
"description": "Headless Laravel authentication core: actions, contracts, result objects and the REST API.",
"keywords": [
"laravel",
"authentication",
Expand Down Expand Up @@ -34,13 +34,13 @@
},
"autoload": {
"psr-4": {
"Simtabi\\Laranail\\Auth\\": "src/"
"Simtabi\\Laranail\\AuthKit\\": "src/"
}
},
"autoload-dev": {
"psr-4": {
"Simtabi\\Laranail\\Auth\\Tests\\": "tests/",
"Simtabi\\Laranail\\Auth\\Database\\Factories\\": "database/factories/",
"Simtabi\\Laranail\\AuthKit\\Tests\\": "tests/",
"Simtabi\\Laranail\\AuthKit\\Database\\Factories\\": "database/factories/",
"Workbench\\App\\": "workbench/app/",
"Workbench\\Database\\Factories\\": "workbench/database/factories/",
"Workbench\\Database\\Seeders\\": "workbench/database/seeders/"
Expand All @@ -49,8 +49,11 @@
"extra": {
"laravel": {
"providers": [
"Simtabi\\Laranail\\Auth\\AuthKitServiceProvider"
"Simtabi\\Laranail\\AuthKit\\AuthKitServiceProvider"
]
},
"branch-alias": {
"dev-main": "0.1.x-dev"
}
},
"repositories": [
Expand All @@ -65,6 +68,14 @@
{
"type": "vcs",
"url": "https://github.com/laranail/package-tools.git"
},
{
"type": "vcs",
"url": "https://github.com/laranail/captcha.git"
},
{
"type": "vcs",
"url": "https://github.com/laranail/db-tools.git"
}
],
"scripts": {
Expand Down
Loading