SanctumGuard
class SanctumGuard implements Guard
Sanctum authentication guard.
Implements GuardContract directly instead of using Laravel's RequestGuard wrapper. This is intentional: RequestGuard stores user state on $this->user which is process-global and unsafe under Swoole. This guard uses coroutine Context for per-request user caching, keyed by token fingerprint.
Token lookup and tokenable resolution are delegated to PersonalAccessToken, which owns all cache logic (token caching, tokenable caching, last_used_at write throttling). This keeps caching co-located with the model rather than split across the guard and model.
Traits
These methods are typically the same across all guards.
Properties
| protected UserProvider|null | $provider | The user provider implementation. |
from GuardHelpers |
| static protected array | $macros | The registered string macros. |
from Macroable |
Methods
Determine if the current user is authenticated. If not, throw an exception.
Mix another object into the class.
Dynamically handle calls to the class.
Dynamically handle calls to the class.
Create a new guard instance.
Get the currently authenticated user.
Determine if the tokenable model supports API tokens.
Get the token from the request.
Get the bearer token from the request headers.
Determine if the bearer token is in the correct format.
Determine if the provided access token is valid.
Determine if the tokenable model matches the provider's model type.
Determine if the guard has a user instance.
Forget the current user.
Validate a user's credentials (not supported for token-based auth).
Get the Context key for caching the authenticated user, keyed by token.
Flush all static state.
Details
in
GuardHelpers at line 32
Authenticatable
authenticate()
Determine if the current user is authenticated. If not, throw an exception.
in
GuardHelpers at line 40
bool
check()
Determine if the current user is authenticated.
in
GuardHelpers at line 48
bool
guest()
Determine if the current user is a guest.
in
GuardHelpers at line 56
int|string|null
id()
Get the ID for the currently authenticated user.
in
GuardHelpers at line 64
UserProvider|null
getProvider()
Get the user provider used by the guard.
in
GuardHelpers at line 75
void
setProvider(UserProvider $provider)
Set the user provider used by the guard.
Boot or tests only. The provider is stored on the worker-lifetime guard and affects every subsequent request.
in
Macroable at line 28
static void
macro(string $name, callable|object $macro)
Register a custom macro.
Boot-only. Macros persist in a static property for the worker lifetime and apply to every subsequent call on the macroable class.
in
Macroable at line 41
static void
mixin(object $mixin, bool $replace = true)
Mix another object into the class.
Boot-only. Delegates to macro() for each method; registered macros persist in a static property for the worker lifetime.
in
Macroable at line 57
static bool
hasMacro(string $name)
Check if macro is registered.
in
Macroable at line 68
static void
flushMacros()
Flush the existing macros.
Boot or tests only. Clears worker-wide macros; concurrent coroutines may resolve different methods depending on timing.
in
Macroable at line 78
static mixed
__callStatic(string $method, array $parameters)
Dynamically handle calls to the class.
in
Macroable at line 103
mixed
__call(string $method, array $parameters)
Dynamically handle calls to the class.
at line 49
__construct(string $name, UserProvider $provider, Container $app, array $sessionGuards, Dispatcher|null $events = null, int|null $expiration = null, bool $trackLastUsedAt = true)
Create a new guard instance.
at line 68
Authenticatable|null
user()
Get the currently authenticated user.
Uses coroutine Context to cache the resolved user per-request, keyed by token fingerprint. A sentinel value caches "no user found" so repeated calls don't trigger redundant lookups.
at line 151
protected bool
supportsTokens(Authenticatable|null $tokenable = null)
Determine if the tokenable model supports API tokens.
at line 161
protected string|null
getTokenFromRequest()
Get the token from the request.
at line 182
protected string|null
getBearerToken(mixed $request)
Get the bearer token from the request headers.
at line 201
protected bool
isValidBearerToken(string|null $token = null)
Determine if the bearer token is in the correct format.
at line 220
protected bool
isValidAccessToken(PersonalAccessToken|null $accessToken)
Determine if the provided access token is valid.
at line 242
protected bool
hasValidProvider(Authenticatable|null $tokenable)
Determine if the tokenable model matches the provider's model type.
at line 256
bool
hasUser()
Determine if the guard has a user instance.
at line 268
Guard
setUser(Authenticatable $user)
Set the current user.
at line 278
SanctumGuard
forgetUser()
Forget the current user.
at line 288
bool
validate(array $credentials = [])
Validate a user's credentials (not supported for token-based auth).
at line 296
protected string
getContextKeyForToken(string|null $token)
Get the Context key for caching the authenticated user, keyed by token.
at line 308
static void
flushState()
Flush all static state.