OpenIdProvider
abstract class OpenIdProvider extends AbstractProvider
Traits
Properties
| static protected int | $nextContextNamespace | The next provider context namespace. |
from HasProviderContext |
| protected string|null | $contextNamespace | The unique context namespace for this provider instance. |
from HasProviderContext |
| protected array | $parameters | The custom parameters to be sent with the request. |
from AbstractProvider |
| protected bool | $stateless | Indicates if the session state should be utilized. |
from AbstractProvider |
| protected array | $additionalConfig | The provider's baseline configuration. |
from AbstractProvider |
| protected array | $scopes | The scopes being requested. |
from AbstractProvider |
| protected string | $scopeSeparator | The separating character for the requested scopes. |
from AbstractProvider |
| protected int | $encodingType | The type of the encoding in the query. |
from AbstractProvider |
| protected bool | $usesPKCE | Indicates if PKCE should be used. |
from AbstractProvider |
| protected null|Closure(array): string | $redirectFormatter | The callback that formats redirect URLs for the provider. |
from AbstractProvider |
| protected null|array{url: string, algorithm: string, keys: array, expiresAt: int} | $jwks | The parsed JSON Web Key Set for the current URI. |
from InteractsWithJwks |
| protected null|array{url: string, algorithm: string, attemptedAt: int} | $jwksRefreshAttempt | The last forced refresh attempt. |
from InteractsWithJwks |
| protected int | $jwksRefreshCooldownSeconds | The minimum seconds between forced JWKS refreshes. |
from InteractsWithJwks |
| protected int | $jwksDefaultTtlSeconds | The fallback lifetime for JWKS responses without cache directives. |
from InteractsWithJwks |
| protected bool | $usesNonce | Indicates if the nonce should be utilized. |
|
| protected null|array{url: string, config: array} | $openidConfig | The OpenID Connect configuration. |
Methods
Get a value from the provider context.
Set a value in the provider context.
Get or set a value in the provider context.
Create a new provider instance.
Set the baseline provider configuration.
Override provider configuration for the current request.
Get a value from the provider configuration.
Set the Guzzle HTTP client instance.
Indicate that the provider should operate as stateless.
Set the custom parameters of the request.
Get the authentication URL for the provider.
Get the token URL for the provider.
Get the raw user for the given access token.
Map the raw user array to a Socialite User instance.
Redirect the user of the application to the provider's authentication screen.
Build the authentication URL for the provider from the given base URL.
Get the GET parameters for the code request.
Format the given scopes.
Create a user instance from the given data.
Get user data by the response from the provider.
Get a Social User instance from a known access token.
Determine if the current request / session has a mismatching "state".
Get the access token response for the given code.
Get the headers for the access token request.
Refresh a user's access token with a refresh token.
Get the refresh token response for the given refresh token.
Parse the access token from a token response.
Parse the refresh token from a token response.
Parse the expiration period from a token response.
Parse the approved scopes from a token response.
Merge the scopes of the requested access.
Set the scopes of the requested access.
Set the callback that formats redirect URLs for the provider.
Validate the token audience for the provider.
Generate a random string of the right length for the PKCE code verifier.
Generate the PKCE code challenge based on the PKCE code verifier in the session.
Return the hash method used to calculate the PKCE code challenge.
Get the jwks URI for the provider.
Decode a token using the provider's JSON Web Key Set.
Get the base URL for the OIDC provider.
Get the user_info URL for the provider.
Determine if the provider is operating with nonce.
Get the string used for nonce.
Get the current string used for nonce.
No description
Get the OpenID Connect configuration URL.
Determine if the current token has a mismatching "nonce".
Get user based on the OIDC token.
Validate the OIDC payload.
Details
in
HasProviderContext at line 30
protected mixed
getContext(string $key, mixed $default = null)
Get a value from the provider context.
in
HasProviderContext at line 38
protected mixed
setContext(string $key, mixed $value)
Set a value in the provider context.
in
HasProviderContext at line 46
protected mixed
getOrSetContext(string $key, mixed $value)
Get or set a value in the provider context.
in
HasProviderContext at line 54
protected void
forgetContext(string $key)
Forget a value from the provider context.
in
HasProviderContext at line 62
protected string
getContextKey(string $key)
Get the context key for the provider.
in
AbstractProvider at line 59
__construct(Request $request, string $clientId, string $clientSecret, Closure|string $redirectUrl, array $guzzle = [])
Create a new provider instance.
in
AbstractProvider at line 52
AbstractProvider
withConfig(array $config)
Set the baseline provider configuration.
Boot-only. The configuration persists for the worker lifetime and affects every subsequent request. Use setConfig() for per-request overrides.
in
AbstractProvider at line 540
AbstractProvider
setConfig(array $config)
Override provider configuration for the current request.
Extends the base setConfig to also handle OAuth2-specific credential keys (client_id, client_secret, redirect) in coroutine context.
in
AbstractProvider at line 77
protected mixed
getConfig(string|null $key = null, mixed $default = null)
Get a value from the provider configuration.
Reads per-request context first, falls back to baseline instance property.
in
AbstractProvider at line 87
protected Client
getHttpClient()
Get an instance of the Guzzle HTTP client.
in
AbstractProvider at line 97
AbstractProvider
setHttpClient(Client $client)
Set the Guzzle HTTP client instance.
in
AbstractProvider at line 110
AbstractProvider
setRequest(Request $request)
Set the request instance.
Stores the request in coroutine context so cached providers read the current request without leaking it to concurrent coroutines.
in
AbstractProvider at line 120
protected Request
getRequest()
Get the request instance.
in
AbstractProvider at line 136
protected bool
usesState()
Determine if the provider is operating with state.
in
AbstractProvider at line 144
protected bool
isStateless()
Determine if the provider is operating as stateless.
in
AbstractProvider at line 152
AbstractProvider
stateless()
Indicate that the provider should operate as stateless.
in
AbstractProvider at line 162
protected string
getState()
Get the string used for session state.
in
AbstractProvider at line 170
AbstractProvider
with(array $parameters)
Set the custom parameters of the request.
in
AbstractProvider at line 180
protected array
getParameters()
Get the custom parameters of the request.
at line 66
protected string
getAuthUrl(string|null $state, string|null $nonce = null)
Get the authentication URL for the provider.
at line 86
protected string
getTokenUrl()
Get the token URL for the provider.
at line 236
protected array
getUserByToken(string $token)
Get the raw user for the given access token.
in
AbstractProvider at line 88
abstract protected User
mapUserToObject(array $user)
Map the raw user array to a Socialite User instance.
at line 43
RedirectResponse
redirect()
Redirect the user of the application to the provider's authentication screen.
at line 78
protected string
buildAuthUrlFromBase(string $url, string|null $state, string|null $nonce = null)
Build the authentication URL for the provider from the given base URL.
at line 110
protected array
getCodeFields(string|null $state = null, string|null $nonce = null)
Get the GET parameters for the code request.
in
AbstractProvider at line 143
protected string
formatScopes(array $scopes, string $scopeSeparator)
Format the given scopes.
in
AbstractProvider at line 154
User
user()
Get the User instance for the authenticated user.
in
AbstractProvider at line 172
protected User|null
getUser()
Get the user instance from the context.
in
AbstractProvider at line 180
protected AbstractProvider
setUser(User $user)
Set the user instance in the context.
in
AbstractProvider at line 190
protected User
userInstance(array $response, array $user)
Create a user instance from the given data.
at line 187
protected array
getUserByTokenResponse(array $response)
Get user data by the response from the provider.
in
AbstractProvider at line 216
User
userFromToken(string $token)
Get a Social User instance from a known access token.
in
AbstractProvider at line 225
protected bool
hasInvalidState()
Determine if the current request / session has a mismatching "state".
in
AbstractProvider at line 239
array
getAccessTokenResponse(string $code)
Get the access token response for the given code.
in
AbstractProvider at line 252
protected array
getTokenHeaders(string $code)
Get the headers for the access token request.
in
AbstractProvider at line 260
protected array
getTokenFields(string $code)
Get the POST fields for the token request.
in
AbstractProvider at line 280
Token
refreshToken(string $refreshToken)
Refresh a user's access token with a refresh token.
in
AbstractProvider at line 295
protected array
getRefreshTokenResponse(string $refreshToken)
Get the refresh token response for the given refresh token.
in
AbstractProvider at line 311
protected string
parseAccessToken(array $response)
Parse the access token from a token response.
in
AbstractProvider at line 319
protected string|null
parseRefreshToken(array $response)
Parse the refresh token from a token response.
in
AbstractProvider at line 327
protected int|null
parseExpiresIn(array $response)
Parse the expiration period from a token response.
in
AbstractProvider at line 348
protected array
parseApprovedScopes(array $response)
Parse the approved scopes from a token response.
in
AbstractProvider at line 362
protected string
getCode()
Get the code from the request.
in
AbstractProvider at line 377
AbstractProvider
scopes(array|string $scopes)
Merge the scopes of the requested access.
in
AbstractProvider at line 389
AbstractProvider
setScopes(array|string $scopes)
Set the scopes of the requested access.
in
AbstractProvider at line 402
array
getScopes()
Get the current scopes.
in
AbstractProvider at line 417
AbstractProvider
withRedirectFormatter(Closure $formatter)
Set the callback that formats redirect URLs for the provider.
Boot-only. The callback persists on the worker-cached provider and affects every subsequent request. Use setConfig() for per-request redirect values.
in
AbstractProvider at line 427
AbstractProvider
redirectUrl(string $url)
Set the redirect URL.
in
AbstractProvider at line 438
protected string
getRedirectUrl()
Get the redirect URL.
in
AbstractProvider at line 458
protected string
getClientId()
Get the client ID.
in
AbstractProvider at line 466
protected string
getClientSecret()
Get the client secret.
in
AbstractProvider at line 474
protected void
validateAudience(mixed $audience)
Validate the token audience for the provider.
in
AbstractProvider at line 493
protected bool
usesPKCE()
Determine if the provider uses PKCE.
in
AbstractProvider at line 501
AbstractProvider
enablePKCE()
Enable PKCE for the provider.
in
AbstractProvider at line 511
protected string
getCodeVerifier()
Generate a random string of the right length for the PKCE code verifier.
in
AbstractProvider at line 519
protected string
getCodeChallenge()
Generate the PKCE code challenge based on the PKCE code verifier in the session.
in
AbstractProvider at line 529
protected string
getCodeChallengeMethod()
Return the hash method used to calculate the PKCE code challenge.
at line 102
protected string
getJwksUri(bool $refresh = false)
Get the jwks URI for the provider.
in
InteractsWithJwks at line 52
protected array
decodeUsingJwks(string $token)
Decode a token using the provider's JSON Web Key Set.
at line 38
abstract protected string
getBaseUrl()
Get the base URL for the OIDC provider.
at line 94
protected string|null
getUserInfoUrl()
Get the user_info URL for the provider.
at line 124
protected bool
usesNonce()
Determine if the provider is operating with nonce.
at line 132
protected string
getNonce()
Get the string used for nonce.
at line 140
protected string|null
getCurrentNonce()
Get the current string used for nonce.
at line 148
protected array
getOpenIdConfig(bool $refresh = false)
No description
at line 179
protected string
getOpenIdConfigUrl()
Get the OpenID Connect configuration URL.
This is used to fetch the OIDC configuration.
at line 196
protected bool
isInvalidNonce(string $nonce)
Determine if the current token has a mismatching "nonce".
nonce must be validated to prevent replay attacks.
at line 208
protected array
getUserByOIDCToken(string $token)
Get user based on the OIDC token.
at line 220
protected void
validateOIDCPayload(array $data)
Validate the OIDC payload.