raxos / oauth2
OAuth2 for raxos/router.
Requires
- php: >=8.5
- jetbrains/phpstorm-attributes: ^1.2
- raxos/cache: *
- raxos/contract: *
- raxos/error: *
- raxos/foundation: *
- raxos/http: *
- raxos/router: *
- raxos/security: *
Requires (Dev)
- pestphp/pest: ^5.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
- dev-main
- 3.2.0
- 3.1.0
- 3.0.1
- 3.0.0
- 2.3.4
- 2.3.3
- 2.3.2
- 2.3.1
- 2.3.0
- 2.2.0
- 2.1.0
- 2.0.7
- 2.0.6
- 2.0.5
- 2.0.4
- 2.0.3
- 2.0.2
- 2.0.1
- 2.0.0
- 1.9.0
- 1.8.2
- 1.8.1
- 1.8.0
- 1.7.0
- 1.6.1
- 1.6.0
- 1.5.1
- 1.5.0
- 1.4.0
- 1.3.3
- 1.3.2
- 1.3.1
- 1.3.0
- 1.2.4
- 1.2.3
- 1.2.2
- 1.2.1
- 1.2.0
- 1.1.2
- 1.1.1
- 1.1.0
- 1.0.20
- 1.0.19
- 1.0.18
- 1.0.17
- 1.0.15
- 1.0.14
- 1.0.13
- 1.0.12
- 1.0.11
- 1.0.10
- 1.0.9
- 1.0.8
- 1.0.7
- 1.0.6
- 1.0.5
- 1.0.4
- 1.0.3
- 1.0.2
- 1.0.1
- 1.0.0
This package is auto-updated.
Last update: 2026-10-03 12:06:39 UTC
README
Raxos OAuth2
OAuth2 authorization-server integration for Raxos Router, with persistence provided by the application.
Documentation | Packagist | Raxos
- Authorization-code and refresh-token grants.
- Authorize, token and revoke controller actions, plus bearer-token middleware.
- Client, scope and token factory contracts implemented by the application.
Installation
Requires PHP 8.5 or later. Composer checks the remaining package and extension dependencies declared in composer.json.
composer require "raxos/oauth2:^3.2"
Usage
<?php declare(strict_types=1); use Raxos\OAuth2\Server\Client\ClientFactoryInterface; use Raxos\OAuth2\Server\OAuth2Server; use Raxos\OAuth2\Server\Scope\ScopeFactoryInterface; use Raxos\OAuth2\Server\Token\TokenFactoryInterface; require __DIR__ . '/vendor/autoload.php'; final class ApplicationOAuth2Server extends OAuth2Server { public function __construct( ClientFactoryInterface $clients, ScopeFactoryInterface $scopes, TokenFactoryInterface $tokens, private readonly ?string $ownerId ) { parent::__construct($clients, $scopes, $tokens); } public function getOwner(): ?string { return $this->ownerId; } public function hasOwner(): bool { return $this->ownerId !== null; } }
Construct this server per request with your factory implementations and the authenticated owner ID, or null for an unauthenticated request. Extend OAuth2Controller to provide the consent and authentication responses, then register that controller with your router. Authorization-code flows require S256 PKCE, exact redirect matching and atomic consumption of unexpired codes by the token factory. See the 3.2 migration guide before implementing storage.
Documentation
Testing
Run this library's Pest suite from the Raxos workspace:
git clone --recurse-submodules https://github.com/basmilius/raxos.git
cd raxos
composer install
vendor/bin/pest --testsuite=oauth2
See Testing Raxos for PHP extensions, integration services and coverage commands. The library's Tests workflow also runs in GitHub Actions.
License
MIT. Copyright (c) 2017 - present Bas Milius.