承接 gcgov/framework-service-auth-ms-front 相关项目开发

从需求分析到上线部署,全程专人跟进,保证项目质量与交付效率

邮箱:yvsm@zunyunkeji.com | QQ:316430983 | 微信:yvsm316

gcgov/framework-service-auth-ms-front

最新稳定版本:v1.1.2

Composer 安装命令:

composer require gcgov/framework-service-auth-ms-front

包简介

Plugins enables the exchange of a Microsoft access token for an application access token. The service assumes the user's front end will handle the authentication flow to acquire and manage the expiration of the Microsoft access token. When the framework app's token expires, user must re-exchange a

README 文档

README

Service to extend gcgov/framework

Primary purpose

  • Enable the exchange of a Microsoft access token for an application access token. The service assumes the user's front end will handle the authentication flow to acquire and manage the expiration of the Microsoft access token. When the framework app's token expires, user must re-exchange a valid Microsoft access token for an updated app access token. There are no app refresh tokens or mechanisms.

Impact to application

  • Router:
    • Adds route /.well-known/jwks.json - provides endpoint to enable front end validation of tokens generated by the api
    • Adds route /auth/microsoft - exchanges a valid Microsoft authentication token for an app access
    • Adds route /auth/fileToken - create a short lived access token that can be used in the url for supported routes

Installation:

Implementation

  • Requests to /auth/microsoft must provide Authorization header with the valid Microsoft access token. Ex Authorization: Bearer {microsoft_token}
  • Response body: { 'access_token':'-app_access_token-', 'expires_in':3600, 'token_type':'Bearer' }

Configuration

Allowed Users

By default, users attempting to sign in who not already present in the user database collection will be prevented from signing in. To enable sign in for any user who passes the third party Oauth provider authentication, set config variable blockNewUsers=false. When blockNewUsers=false, any user successfully authenticated by the third party Oauth provider will be automatically added to the database user config

$msAuthConfig = msAuthConfig::getInstance();
$msAuthConfig->setBlockNewUsers( false );

New User Default Roles

When blockNewUsers=false, new users will be automatically added to the user database collection. To set the default roles that a new user should be assigned at creation, provide the roles to the setBlockNewUsers method.

$msAuthConfig = msAuthConfig::getInstance();
$msAuthConfig->setBlockNewUsers( false, [ 'Role1.Read', 'Role2.Read', 'Role2.Write' ] );

统计信息

  • 总下载量: 7
  • 月度下载量: 0
  • 日度下载量: 0
  • 收藏数: 0
  • 点击次数: 1
  • 依赖项目数: 0
  • 推荐数: 0

GitHub 信息

  • Stars: 0
  • Watchers: 1
  • Forks: 0
  • 开发语言: PHP

其他信息

  • 授权协议: MIT
  • 更新时间: 2023-08-07