Search by

raxos / oauth2

basmilius

OAuth2 for raxos/router.

3.2.0 2026-10-02 17:11 UTC

README

Bas Milius

Raxos OAuth2

OAuth2 authorization-server integration for Raxos Router, with persistence provided by the application.

Documentation | Packagist | Raxos

  • Authorization-code and refresh-token grants.
  • Authorize, token and revoke controller actions, plus bearer-token middleware.
  • Client, scope and token factory contracts implemented by the application.

Installation

Requires PHP 8.5 or later. Composer checks the remaining package and extension dependencies declared in composer.json.

composer require "raxos/oauth2:^3.2"

Usage

<?php
declare(strict_types=1);

use Raxos\OAuth2\Server\Client\ClientFactoryInterface;
use Raxos\OAuth2\Server\OAuth2Server;
use Raxos\OAuth2\Server\Scope\ScopeFactoryInterface;
use Raxos\OAuth2\Server\Token\TokenFactoryInterface;

require __DIR__ . '/vendor/autoload.php';

final class ApplicationOAuth2Server extends OAuth2Server
{
    public function __construct(
        ClientFactoryInterface $clients,
        ScopeFactoryInterface $scopes,
        TokenFactoryInterface $tokens,
        private readonly ?string $ownerId
    )
    {
        parent::__construct($clients, $scopes, $tokens);
    }

    public function getOwner(): ?string
    {
        return $this->ownerId;
    }

    public function hasOwner(): bool
    {
        return $this->ownerId !== null;
    }
}

Construct this server per request with your factory implementations and the authenticated owner ID, or null for an unauthenticated request. Extend OAuth2Controller to provide the consent and authentication responses, then register that controller with your router. Authorization-code flows require S256 PKCE, exact redirect matching and atomic consumption of unexpired codes by the token factory. See the 3.2 migration guide before implementing storage.

Documentation

Testing

Run this library's Pest suite from the Raxos workspace:

git clone --recurse-submodules https://github.com/basmilius/raxos.git
cd raxos
composer install
vendor/bin/pest --testsuite=oauth2

See Testing Raxos for PHP extensions, integration services and coverage commands. The library's Tests workflow also runs in GitHub Actions.

License

MIT. Copyright (c) 2017 - present Bas Milius.