anwar / auto-login
Larvel Multiple App AutoLogin from single app...
Requires
None
Requires (Dev)
- orchestra/testbench: ^6.0
- phpunit/phpunit: ^9.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-29 11:52:58 UTC
README
Single sign-on across multiple Laravel applications from one central app.
A user proves their credentials to the central app, receives a token, and that token can be handed to any sibling application to establish a session without re-entering the password.
Installation
composer require anwar/auto-login
php artisan vendor:publish --tag=config --provider="Anwar\AutoLogin\AutoLoginServiceProvider"
php artisan migrate
The migration adds two columns to your users table:
app_token— stores the SHA-256 hash of the current tokenapp_reference— records where the token was issued
Usage
1. Obtain a token (central app)
POST /auto-login/generate_token Content-Type: application/json { "email": "user@example.com", "password": "secret" }
Response:
{ "status": true, "app_token": "<plaintext-token>" }
The plaintext token is returned once. Only its hash is stored.
2. Consume a token (sibling app)
GET /auto-login?app_token=<plaintext-token>
On success the user is authenticated and redirected to
config('autologin.redirect_to') (default /).
Security
This package is designed to be safe by default:
- Hashed at rest — only
sha256(token)is stored. A database leak cannot be replayed. - Active accounts only — tokens are issued/consumed only for
active = 1andis_delete = 0users (configurable viarequire_active). - No user enumeration — failures return a generic message.
- Session fixation protection — the session id is regenerated on login.
- Rate limited —
generate_token(10/min) andauto-login(20/min). - Optional shared secret — set
AUTOLOGIN_SHARED_SECRET(orshared_secretin config) to require anX-AutoLogin-Secretheader ongenerate_tokenfor server-to-server calls. - Legacy migration — existing plaintext tokens keep working and are transparently upgraded to a hash on first use.
Configuration
// config/autologin.php return [ 'users_table' => 'users', 'redirect_to' => '/', 'require_active' => true, 'shared_secret' => env('AUTOLOGIN_SHARED_SECRET', ''), 'token_length' => 64, ];
Important
- Always serve
generate_tokenandauto-loginover HTTPS. - Rotate a user's token by calling
generate_tokenagain (invalidates the old one). - The browser-facing
auto-loginroute must not be CSRF-exempt; only the machine-to-machinegenerate_tokencall needs to be inVerifyCsrfToken::$except.
Testing
composer test
Changelog
See CHANGELOG.
License
The MIT License (MIT). See LICENSE.