{"id":14983672,"url":"https://github.com/jdelaune/oauth2-client-bundle","last_synced_at":"2025-04-10T19:04:31.978Z","repository":{"id":10577048,"uuid":"12784783","full_name":"jdelaune/oauth2-client-bundle","owner":"jdelaune","description":"Symfony 2-4 OAuth2 Client Bundle","archived":false,"fork":false,"pushed_at":"2019-12-17T12:11:43.000Z","size":41,"stargazers_count":5,"open_issues_count":1,"forks_count":5,"subscribers_count":2,"default_branch":"3.x","last_synced_at":"2025-03-24T16:46:01.475Z","etag":null,"topics":["oauth2","oauth2-client","symfony","symfony2","symfony3","symfony4"],"latest_commit_sha":null,"homepage":"","language":"PHP","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/jdelaune.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"Security/Authentication/Provider/OAuth2Provider.php","support":null}},"created_at":"2013-09-12T13:45:43.000Z","updated_at":"2019-12-17T12:01:24.000Z","dependencies_parsed_at":"2022-09-22T20:11:40.166Z","dependency_job_id":null,"html_url":"https://github.com/jdelaune/oauth2-client-bundle","commit_stats":null,"previous_names":[],"tags_count":13,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jdelaune%2Foauth2-client-bundle","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jdelaune%2Foauth2-client-bundle/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jdelaune%2Foauth2-client-bundle/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jdelaune%2Foauth2-client-bundle/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/jdelaune","download_url":"https://codeload.github.com/jdelaune/oauth2-client-bundle/tar.gz/refs/heads/3.x","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248279196,"owners_count":21077406,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["oauth2","oauth2-client","symfony","symfony2","symfony3","symfony4"],"created_at":"2024-09-24T14:07:45.772Z","updated_at":"2025-04-10T19:04:31.958Z","avatar_url":"https://github.com/jdelaune.png","language":"PHP","funding_links":[],"categories":[],"sub_categories":[],"readme":"# OAuth2 Client Bundle\n\nOAuth2 Client Bundle for Symfony 2-5.\n\n## Overview\n\nAllow for the protection of resources via OAuth2. Provides two Symfony firewalls. One for checking bearer access tokens for securing API application. The access tokens can be provided via a header (recommended) or query e.g. `Authorization: Bearer {Access Token}` or `http://example.com/resource?access_token={Access Token}`. The other firewall is for securing web applications via the authorization code grant type.\n\n## Installation\n\n### Step 1: Add package to Composer\n\nAdd the bundle to your composer.json:\n\n``` js\n{\n    \"require\": {\n        \"jdelaune/oauth2-client-bundle\": \"^5.0\"\n    }\n}\n```\n\nNow tell composer to download the bundle by running the command:\n\n``` bash\n$ php composer.phar update jdelaune/oauth2-client-bundle\n```\n\nComposer will install the bundle to your project's `vendor/jdelaune` directory.\n\n### Step 2: Enable the bundle\n\nEnable the bundle in the kernel:\n\n``` php\n\u003c?php\n// app/AppKernel.php\n\npublic function registerBundles()\n{\n    $bundles = array(\n        // ...\n        new OAuth2\\ClientBundle\\OAuth2ClientBundle(),\n    );\n}\n```\n\n### Step 3: Add parameters\n\nYou'll need add your OAuth2 Server URIs as parameters to your `parameters.yml`\n\n``` yaml\n# app/config/parameters.yml\n\nparameters:\n    oauth2.client.server:\n        authorize_uri: 'http://example.com/authorize'\n        token_uri: 'https://example.com/token'\n        verify_uri: 'https://example.com/verify-token'\n        validate_ssl: true\n```\n\nThe verify uri should verify the access token on your OAuth2 Server and provide a JSON encoded array of:\n\n- `access_token`\n- `client_id`\n- `expires_in`\n- `user_id` (Optional)\n- `scope` (Optional)\n\n### Step 4a: Configure security (access token)\n\nAccess token only firewall is most often used for securing APIs where the end user won't actually be interacting with your Symfony application directly.\n\nYou'll need to setup a firewall in your `security.yml`\n\n``` yaml\n# app/config/security.yml\n\nsecurity:\n    encoders:\n        OAuth2\\ClientBundle\\Security\\User\\OAuth2User: plaintext\n\n    providers:\n        oauth2_client:\n            id: oauth2.client.user_provider\n\n    firewalls:\n        oauth2_secured:\n            pattern: ^/secured_area/\n            oauth2_access_token: true\n            stateless: true\n```\n\n### Step 4b: Configure security (authorization code)\n\nAuthorization code firewall is most often used when the end user is interacting with your Symfony application.\n\nYou'll need to setup a firewall in your `security.yml`\n\n``` yaml\n# app/config/security.yml\n\nsecurity:\n    encoders:\n        OAuth2\\ClientBundle\\Security\\User\\OAuth2User: plaintext\n\n    providers:\n        oauth2_client:\n            id: oauth2.client.user_provider\n\n    firewalls:\n        oauth2_secured:\n            pattern: ^/secured_area/\n            oauth2_authorization_code:\n                client_id: ~\n                client_secret: ~\n                redirect_uri: http://www.example.com/secured_area/authorized\n                scope: basic\n```\n\nThe `redirect_uri` needs to be a URI behind the same firewall. You can use all the usual configuration options here as well that one would use for the form firewall like `use_referer` and `default_target_path`.\n\n### Step 5: Add routing\n\nWe provide default routing for some paths needed when using the authorization code firewall. Add this to your `routing.yml`\n\n``` yaml\n# app/config/routing.yml\n\noauth2_client:\n    resource: \"@OAuth2ClientBundle/Controller/\"\n    type:     annotation\n    prefix:   /\n```\n\n## The OAuth2Token\n\nThe client bundle will provide an `OAuth2Token` object for any secured path in your controllers.\n\nThere are additional getters available on the `OAuth2User` object:\n\n``` php\n$token = $this-\u003eget('security.context')-\u003egetToken();\n$token-\u003egetAccessToken(); // The access token\n$token-\u003egetRefreshToken(); // The refresh token\n$token-\u003egetExpiresAt(); // Expiry datetime object\n$token-\u003egetExpiresIn(); // Seconds until the access token expires\n```\n\n## The OAuth2User\n\nThe client bundle will provide an `OAuth2User` object for any secured path in your controllers.\n\nScopes will be turned into roles automatically, e.g. a scope of `email` would result in a role of `ROLE_EMAIL`.\n\nThere are additional getters available on the `OAuth2User` object:\n\n``` php\n$user = $this-\u003egetUser();\n$user-\u003egetClientId(); // Client ID\n$user-\u003egetUserId(); // User ID\n$user-\u003eisUser(); // True if user, false if client only\n$user-\u003egetUsername(); // Client ID if client only, or User ID if user\n$user-\u003egetScopes(); // Array of scopes\n$user-\u003egetAccessToken(); // The access token\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjdelaune%2Foauth2-client-bundle","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjdelaune%2Foauth2-client-bundle","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjdelaune%2Foauth2-client-bundle/lists"}