abstract class OpenIdProvider extends AbstractProvider

Traits

Properties

static protected int $nextContextNamespace

The next provider context namespace.

from  HasProviderContext
protected string|null $contextNamespace

The unique context namespace for this provider instance.

from  HasProviderContext
protected array $parameters

The custom parameters to be sent with the request.

from  AbstractProvider
protected bool $stateless

Indicates if the session state should be utilized.

from  AbstractProvider
protected array $additionalConfig

The provider's baseline configuration.

from  AbstractProvider
protected array $scopes

The scopes being requested.

from  AbstractProvider
protected string $scopeSeparator

The separating character for the requested scopes.

from  AbstractProvider
protected int $encodingType

The type of the encoding in the query.

from  AbstractProvider
protected bool $usesPKCE

Indicates if PKCE should be used.

from  AbstractProvider
protected null|Closure(array): string $redirectFormatter

The callback that formats redirect URLs for the provider.

from  AbstractProvider
protected null|array{url: string, algorithm: string, keys: array, expiresAt: int} $jwks

The parsed JSON Web Key Set for the current URI.

from  InteractsWithJwks
protected null|array{url: string, algorithm: string, attemptedAt: int} $jwksRefreshAttempt

The last forced refresh attempt.

from  InteractsWithJwks
protected int $jwksRefreshCooldownSeconds

The minimum seconds between forced JWKS refreshes.

from  InteractsWithJwks
protected int $jwksDefaultTtlSeconds

The fallback lifetime for JWKS responses without cache directives.

from  InteractsWithJwks
protected bool $usesNonce

Indicates if the nonce should be utilized.

protected null|array{url: string, config: array} $openidConfig

The OpenID Connect configuration.

Methods

mixed
getContext(string $key, mixed $default = null)

Get a value from the provider context.

mixed
setContext(string $key, mixed $value)

Set a value in the provider context.

mixed
getOrSetContext(string $key, mixed $value)

Get or set a value in the provider context.

void
forgetContext(string $key)

Forget a value from the provider context.

string
getContextKey(string $key)

Get the context key for the provider.

__construct(Request $request, string $clientId, string $clientSecret, Closure|string $redirectUrl, array $guzzle = [])

Create a new provider instance.

withConfig(array $config)

Set the baseline provider configuration.

setConfig(array $config)

Override provider configuration for the current request.

mixed
getConfig(string|null $key = null, mixed $default = null)

Get a value from the provider configuration.

Client
getHttpClient()

Get an instance of the Guzzle HTTP client.

setHttpClient(Client $client)

Set the Guzzle HTTP client instance.

setRequest(Request $request)

Set the request instance.

getRequest()

Get the request instance.

bool
usesState()

Determine if the provider is operating with state.

bool
isStateless()

Determine if the provider is operating as stateless.

stateless()

Indicate that the provider should operate as stateless.

string
getState()

Get the string used for session state.

with(array $parameters)

Set the custom parameters of the request.

array
getParameters()

Get the custom parameters of the request.

string
getAuthUrl(string|null $state, string|null $nonce = null)

Get the authentication URL for the provider.

string
getTokenUrl()

Get the token URL for the provider.

array
getUserByToken(string $token)

Get the raw user for the given access token.

mapUserToObject(array $user)

Map the raw user array to a Socialite User instance.

redirect()

Redirect the user of the application to the provider's authentication screen.

string
buildAuthUrlFromBase(string $url, string|null $state, string|null $nonce = null)

Build the authentication URL for the provider from the given base URL.

array
getCodeFields(string|null $state = null, string|null $nonce = null)

Get the GET parameters for the code request.

string
formatScopes(array $scopes, string $scopeSeparator)

Format the given scopes.

user()

Get the User instance for the authenticated user.

User|null
getUser()

Get the user instance from the context.

setUser(User $user)

Set the user instance in the context.

userInstance(array $response, array $user)

Create a user instance from the given data.

array
getUserByTokenResponse(array $response)

Get user data by the response from the provider.

userFromToken(string $token)

Get a Social User instance from a known access token.

bool
hasInvalidState()

Determine if the current request / session has a mismatching "state".

array
getAccessTokenResponse(string $code)

Get the access token response for the given code.

array
getTokenHeaders(string $code)

Get the headers for the access token request.

array
getTokenFields(string $code)

Get the POST fields for the token request.

refreshToken(string $refreshToken)

Refresh a user's access token with a refresh token.

array
getRefreshTokenResponse(string $refreshToken)

Get the refresh token response for the given refresh token.

string
parseAccessToken(array $response)

Parse the access token from a token response.

string|null
parseRefreshToken(array $response)

Parse the refresh token from a token response.

int|null
parseExpiresIn(array $response)

Parse the expiration period from a token response.

array
parseApprovedScopes(array $response)

Parse the approved scopes from a token response.

string
getCode()

Get the code from the request.

scopes(array|string $scopes)

Merge the scopes of the requested access.

setScopes(array|string $scopes)

Set the scopes of the requested access.

array
getScopes()

Get the current scopes.

withRedirectFormatter(Closure $formatter)

Set the callback that formats redirect URLs for the provider.

redirectUrl(string $url)

Set the redirect URL.

string
getRedirectUrl()

Get the redirect URL.

string
getClientId()

Get the client ID.

string
getClientSecret()

Get the client secret.

void
validateAudience(mixed $audience)

Validate the token audience for the provider.

bool
usesPKCE()

Determine if the provider uses PKCE.

enablePKCE()

Enable PKCE for the provider.

string
getCodeVerifier()

Generate a random string of the right length for the PKCE code verifier.

string
getCodeChallenge()

Generate the PKCE code challenge based on the PKCE code verifier in the session.

string
getCodeChallengeMethod()

Return the hash method used to calculate the PKCE code challenge.

string
getJwksUri(bool $refresh = false)

Get the jwks URI for the provider.

array
decodeUsingJwks(string $token)

Decode a token using the provider's JSON Web Key Set.

string
getBaseUrl()

Get the base URL for the OIDC provider.

string|null
getUserInfoUrl()

Get the user_info URL for the provider.

bool
usesNonce()

Determine if the provider is operating with nonce.

string
getNonce()

Get the string used for nonce.

string|null
getCurrentNonce()

Get the current string used for nonce.

array
getOpenIdConfig(bool $refresh = false)

No description

string
getOpenIdConfigUrl()

Get the OpenID Connect configuration URL.

bool
isInvalidNonce(string $nonce)

Determine if the current token has a mismatching "nonce".

array
getUserByOIDCToken(string $token)

Get user based on the OIDC token.

void
validateOIDCPayload(array $data)

Validate the OIDC payload.

Details

in HasProviderContext at line 30
protected mixed getContext(string $key, mixed $default = null)

Get a value from the provider context.

Parameters

string $key
mixed $default

Return Value

mixed

in HasProviderContext at line 38
protected mixed setContext(string $key, mixed $value)

Set a value in the provider context.

Parameters

string $key
mixed $value

Return Value

mixed

in HasProviderContext at line 46
protected mixed getOrSetContext(string $key, mixed $value)

Get or set a value in the provider context.

Parameters

string $key
mixed $value

Return Value

mixed

in HasProviderContext at line 54
protected void forgetContext(string $key)

Forget a value from the provider context.

Parameters

string $key

Return Value

void

in HasProviderContext at line 62
protected string getContextKey(string $key)

Get the context key for the provider.

Parameters

string $key

Return Value

string

in AbstractProvider at line 59
__construct(Request $request, string $clientId, string $clientSecret, Closure|string $redirectUrl, array $guzzle = [])

Create a new provider instance.

Parameters

Request $request
string $clientId

the client ID

string $clientSecret

the client secret

Closure|string $redirectUrl

the redirect URL

array $guzzle

in AbstractProvider at line 52
AbstractProvider withConfig(array $config)

Set the baseline provider configuration.

Boot-only. The configuration persists for the worker lifetime and affects every subsequent request. Use setConfig() for per-request overrides.

Parameters

array $config

Return Value

AbstractProvider

in AbstractProvider at line 540
AbstractProvider setConfig(array $config)

Override provider configuration for the current request.

Extends the base setConfig to also handle OAuth2-specific credential keys (client_id, client_secret, redirect) in coroutine context.

Parameters

array $config

Return Value

AbstractProvider

in AbstractProvider at line 77
protected mixed getConfig(string|null $key = null, mixed $default = null)

Get a value from the provider configuration.

Reads per-request context first, falls back to baseline instance property.

Parameters

string|null $key
mixed $default

Return Value

mixed

in AbstractProvider at line 87
protected Client getHttpClient()

Get an instance of the Guzzle HTTP client.

Return Value

Client

in AbstractProvider at line 97
AbstractProvider setHttpClient(Client $client)

Set the Guzzle HTTP client instance.

Parameters

Client $client

Return Value

AbstractProvider

in AbstractProvider at line 110
AbstractProvider setRequest(Request $request)

Set the request instance.

Stores the request in coroutine context so cached providers read the current request without leaking it to concurrent coroutines.

Parameters

Request $request

Return Value

AbstractProvider

in AbstractProvider at line 120
protected Request getRequest()

Get the request instance.

Return Value

Request

in AbstractProvider at line 136
protected bool usesState()

Determine if the provider is operating with state.

Return Value

bool

in AbstractProvider at line 144
protected bool isStateless()

Determine if the provider is operating as stateless.

Return Value

bool

in AbstractProvider at line 152
AbstractProvider stateless()

Indicate that the provider should operate as stateless.

Return Value

AbstractProvider

in AbstractProvider at line 162
protected string getState()

Get the string used for session state.

Return Value

string

in AbstractProvider at line 170
AbstractProvider with(array $parameters)

Set the custom parameters of the request.

Parameters

array $parameters

Return Value

AbstractProvider

in AbstractProvider at line 180
protected array getParameters()

Get the custom parameters of the request.

Return Value

array

at line 66
protected string getAuthUrl(string|null $state, string|null $nonce = null)

Get the authentication URL for the provider.

Parameters

string|null $state
string|null $nonce

Return Value

string

at line 86
protected string getTokenUrl()

Get the token URL for the provider.

Return Value

string

at line 236
protected array getUserByToken(string $token)

Get the raw user for the given access token.

Parameters

string $token

Return Value

array

in AbstractProvider at line 88
abstract protected User mapUserToObject(array $user)

Map the raw user array to a Socialite User instance.

Parameters

array $user

Return Value

User

at line 43
RedirectResponse redirect()

Redirect the user of the application to the provider's authentication screen.

Return Value

RedirectResponse

at line 78
protected string buildAuthUrlFromBase(string $url, string|null $state, string|null $nonce = null)

Build the authentication URL for the provider from the given base URL.

Parameters

string $url
string|null $state
string|null $nonce

Return Value

string

at line 110
protected array getCodeFields(string|null $state = null, string|null $nonce = null)

Get the GET parameters for the code request.

Parameters

string|null $state
string|null $nonce

Return Value

array

in AbstractProvider at line 143
protected string formatScopes(array $scopes, string $scopeSeparator)

Format the given scopes.

Parameters

array $scopes
string $scopeSeparator

Return Value

string

in AbstractProvider at line 154
User user()

Get the User instance for the authenticated user.

in AbstractProvider at line 172
protected User|null getUser()

Get the user instance from the context.

Return Value

User|null

in AbstractProvider at line 180
protected AbstractProvider setUser(User $user)

Set the user instance in the context.

Parameters

User $user

Return Value

AbstractProvider

in AbstractProvider at line 190
protected User userInstance(array $response, array $user)

Create a user instance from the given data.

Parameters

array $response
array $user

Return Value

User

at line 187
protected array getUserByTokenResponse(array $response)

Get user data by the response from the provider.

Parameters

array $response

Return Value

array

in AbstractProvider at line 216
User userFromToken(string $token)

Get a Social User instance from a known access token.

Parameters

string $token

Return Value

User

in AbstractProvider at line 225
protected bool hasInvalidState()

Determine if the current request / session has a mismatching "state".

Return Value

bool

in AbstractProvider at line 239
array getAccessTokenResponse(string $code)

Get the access token response for the given code.

Parameters

string $code

Return Value

array

in AbstractProvider at line 252
protected array getTokenHeaders(string $code)

Get the headers for the access token request.

Parameters

string $code

Return Value

array

in AbstractProvider at line 260
protected array getTokenFields(string $code)

Get the POST fields for the token request.

Parameters

string $code

Return Value

array

in AbstractProvider at line 280
Token refreshToken(string $refreshToken)

Refresh a user's access token with a refresh token.

Parameters

string $refreshToken

Return Value

Token

in AbstractProvider at line 295
protected array getRefreshTokenResponse(string $refreshToken)

Get the refresh token response for the given refresh token.

Parameters

string $refreshToken

Return Value

array

in AbstractProvider at line 311
protected string parseAccessToken(array $response)

Parse the access token from a token response.

Parameters

array $response

Return Value

string

in AbstractProvider at line 319
protected string|null parseRefreshToken(array $response)

Parse the refresh token from a token response.

Parameters

array $response

Return Value

string|null

in AbstractProvider at line 327
protected int|null parseExpiresIn(array $response)

Parse the expiration period from a token response.

Parameters

array $response

Return Value

int|null

in AbstractProvider at line 348
protected array parseApprovedScopes(array $response)

Parse the approved scopes from a token response.

Parameters

array $response

Return Value

array

in AbstractProvider at line 362
protected string getCode()

Get the code from the request.

Return Value

string

Exceptions

InvalidCodeException

in AbstractProvider at line 377
AbstractProvider scopes(array|string $scopes)

Merge the scopes of the requested access.

Parameters

array|string $scopes

Return Value

AbstractProvider

in AbstractProvider at line 389
AbstractProvider setScopes(array|string $scopes)

Set the scopes of the requested access.

Parameters

array|string $scopes

Return Value

AbstractProvider

in AbstractProvider at line 402
array getScopes()

Get the current scopes.

Return Value

array

in AbstractProvider at line 417
AbstractProvider withRedirectFormatter(Closure $formatter)

Set the callback that formats redirect URLs for the provider.

Boot-only. The callback persists on the worker-cached provider and affects every subsequent request. Use setConfig() for per-request redirect values.

Parameters

Closure $formatter

Return Value

AbstractProvider

in AbstractProvider at line 427
AbstractProvider redirectUrl(string $url)

Set the redirect URL.

Parameters

string $url

Return Value

AbstractProvider

in AbstractProvider at line 438
protected string getRedirectUrl()

Get the redirect URL.

Return Value

string

in AbstractProvider at line 458
protected string getClientId()

Get the client ID.

Return Value

string

in AbstractProvider at line 466
protected string getClientSecret()

Get the client secret.

Return Value

string

in AbstractProvider at line 474
protected void validateAudience(mixed $audience)

Validate the token audience for the provider.

Parameters

mixed $audience

Return Value

void

in AbstractProvider at line 493
protected bool usesPKCE()

Determine if the provider uses PKCE.

Return Value

bool

in AbstractProvider at line 501
AbstractProvider enablePKCE()

Enable PKCE for the provider.

Return Value

AbstractProvider

in AbstractProvider at line 511
protected string getCodeVerifier()

Generate a random string of the right length for the PKCE code verifier.

Return Value

string

in AbstractProvider at line 519
protected string getCodeChallenge()

Generate the PKCE code challenge based on the PKCE code verifier in the session.

Return Value

string

in AbstractProvider at line 529
protected string getCodeChallengeMethod()

Return the hash method used to calculate the PKCE code challenge.

Return Value

string

at line 102
protected string getJwksUri(bool $refresh = false)

Get the jwks URI for the provider.

Parameters

bool $refresh

Return Value

string

in InteractsWithJwks at line 52
protected array decodeUsingJwks(string $token)

Decode a token using the provider's JSON Web Key Set.

Parameters

string $token

Return Value

array

at line 38
abstract protected string getBaseUrl()

Get the base URL for the OIDC provider.

Return Value

string

at line 94
protected string|null getUserInfoUrl()

Get the user_info URL for the provider.

Return Value

string|null

at line 124
protected bool usesNonce()

Determine if the provider is operating with nonce.

Return Value

bool

at line 132
protected string getNonce()

Get the string used for nonce.

Return Value

string

at line 140
protected string|null getCurrentNonce()

Get the current string used for nonce.

Return Value

string|null

at line 148
protected array getOpenIdConfig(bool $refresh = false)

No description

Parameters

bool $refresh

Return Value

array

Exceptions

ConfigurationFetchingException

at line 179
protected string getOpenIdConfigUrl()

Get the OpenID Connect configuration URL.

This is used to fetch the OIDC configuration.

Return Value

string

at line 196
protected bool isInvalidNonce(string $nonce)

Determine if the current token has a mismatching "nonce".

nonce must be validated to prevent replay attacks.

Parameters

string $nonce

Return Value

bool

at line 208
protected array getUserByOIDCToken(string $token)

Get user based on the OIDC token.

Parameters

string $token

Return Value

array

at line 220
protected void validateOIDCPayload(array $data)

Validate the OIDC payload.

Parameters

array $data

Return Value

void