Search by

light-it-labs / lightit-auth-laravel

soj3da

An optional-feature authentication package for Laravel projects. It layers Google SSO, 2FA, OTP, forgot password and role-permission systems on top of a boilerplate that already owns base authentication, with standardized examples for seamless integration into your projects.

Package info

github.com/Light-it-labs/lightit-auth-laravel

Homepage

pkg:composer/light-it-labs/lightit-auth-laravel

Fund package maintenance!

Light-it Labs

Statistics

Installs: 24

Dependents: 0

Suggesters: 0

Stars: 3

Open Issues: 6

1.3.0 2026-04-30 18:06 UTC

This package is auto-updated.

Last update: 2026-10-07 00:45:05 UTC


README

Laravel Auth Package

Laravel Auth Package adds optional auth features - 2FA, roles and permissions, OTP, forgot password and social login - on top of the Light-it Laravel Boilerplate, which owns the base authentication. Supporting the following packages

Contents

Installation

Important

This package is based on and tightly coupled with the Light-it Laravel Boilerplate.
It assumes conventions like:

  • Main namespace: Lightit
  • Specific file paths
  • Custom exceptions structure

Keep this in mind if you plan to integrate it into a different project.

First, add the repository to your composer.json:

{
    "repositories": [
        {
            "type": "vcs",
            "url": "https://github.com/Light-it-labs/lightit-auth-laravel.git"
        }
    ]
}

Then install the package via Composer:

composer require light-it-labs/lightit-auth-laravel

Keep it a runtime dependency (never composer require --dev): if you select Two-Factor Authentication, the package's own service provider registers the 2fa rate limiter on boot, and that provider needs to be loaded in production for the limiter to exist.

Once installed, run the setup command:

php artisan auth:setup

If you are using Laravel Sail, you can run:

./vendor/bin/sail artisan auth:setup

This command walks you through the optional features it can add on top of the boilerplate's own authentication. It no longer configures an authentication driver.

If the 2FA frontend layer can't find a React project next to your Laravel app (a sibling directory named frontend, front, or <app>-frontend), pass its path explicitly with --frontend-path=<path>. Relative paths resolve against the Laravel application root, not your shell's current directory. The frontend layer is only generated when Two-Factor Authentication is selected, but an invalid explicit path fails the whole command even if Two-Factor Authentication is not selected.

For each feature that needs manual steps, auth:setup prints them and leaves a short checklist next to the code it wrote: AUTH-<FEATURE>-TODO.md in the backend root and AUTH-<FEATURE>-FRONTEND-TODO.md in the frontend root. Tick the boxes, then delete the file: nothing reads it. The feature's page under docs/ explains every step in full.

Changelog

For recent changes, see the CHANGELOG.

Security Vulnerabilities

Please review our security policy on how to report security vulnerabilities.

Credits

License

The MIT License (MIT). Please see License File for more information.