loongs / oauth
loong-swoole OAuth 2.1 authorization server + resource server — authorization_code with PKCE (S256), client_credentials, rotating refresh tokens, RFC 7009 revocation, RFC 7662 introspection, RFC 8414 metadata, RFC 9207 iss, encrypted RFC 9068 access tokens (nested JWS-in-JWE, RFC 7516); storage-agno
dev-main
2026-10-08 02:52 UTC
Requires
- php: ^8.4
- ext-json: *
- ext-openssl: *
- loongs/helper: dev-main
Requires (Dev)
None
Suggests
- ext-sodium: Not required; random_bytes() (CSPRNG) is used for every secret
- loongs/cache: CacheTokenStorage: authorization codes and tokens in Redis (or any loongs/cache store)
- loongs/framework: BearerMiddleware (resource server), OAuthRoutes (authorization server endpoints), oauth:install console command
- loongs/orm: OrmStorage: MySQL storage (explicit connection spec or the default connection); OrmStorage::installOn() / ./loongs oauth:install create the tables
- loongs/saas: One set of OAuth tables per tenant: new OrmStorage() follows the Tenancy::run() tenant scope
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-10-08 02:52:26 UTC