A spec compliant, secure by default PHP OAuth 2.0 Server
Go to file
2017-07-01 18:37:54 +01:00
examples Apply fixes from StyleCI 2017-07-01 16:19:23 +00:00
src Apply fixes from StyleCI 2017-07-01 16:19:23 +00:00
tests New property on AuthorizationServer to receive an encryption key which is used for future encryption/decryption instead of keybased encryption/decryption 2017-07-01 16:45:29 +01:00
.gitattributes Updated .gitignore / .gitattributes files 2016-02-12 17:51:28 +00:00
.gitignore Updated .gitignore / .gitattributes files 2016-02-12 17:51:28 +00:00
.scrutinizer.yml Updated .scrutenizer.yml 2016-04-18 12:23:13 +01:00
.styleci.yml Create .styleci.yml 2016-02-19 23:08:32 +00:00
.travis.yml Removed HHVM from .travis.yml 2017-07-01 18:34:53 +01:00
CHANGELOG.md Updated changelog and readme 2017-07-01 17:17:55 +01:00
composer.json Updated random_compat version 2017-07-01 16:45:29 +01:00
CONDUCT.md Added code of conduct 2016-01-13 00:46:18 +00:00
CONTRIBUTING.md Update CONTRIBUTING.md 2013-12-06 10:50:22 +00:00
LICENSE Rename license file 2015-12-03 14:30:37 +01:00
phpunit.xml.dist Ignore TemplateRenderer method 2016-03-10 17:45:31 +00:00
README.md 5.1.4 not 5.1.14 2017-07-01 18:37:54 +01:00

PHP OAuth 2.0 Server

⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️

Security Notice

Please upgrade to version >=5.1.4 (backwards compatible) or 6.x (one tiny breaking change) to fix some potential security vulnerabilities

⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️

Latest Version Software License Build Status Coverage Status Quality Score Total Downloads

league/oauth2-server is a standards compliant implementation of an OAuth 2.0 authorization server written in PHP which makes working with OAuth 2.0 trivial. You can easily configure an OAuth 2.0 server to protect your API with access tokens, or allow clients to request new access tokens and refresh them.

It supports out of the box the following grants:

  • Authorization code grant
  • Implicit grant
  • Client credentials grant
  • Resource owner password credentials grant
  • Refresh grant

The following RFCs are implemented:

This library was created by Alex Bilbie. Find him on Twitter at @alexbilbie.

Requirements

The following versions of PHP are supported:

  • PHP 5.5 (>=5.5.9)
  • PHP 5.6
  • PHP 7.0
  • PHP 7.1
  • HHVM

The openssl extension is also required.

Documentation

The library documentation can be found at https://oauth2.thephpleague.com. You can contribute to the documentation in the gh-pages branch.

Changelog

See the project releases page

Contributing

Please see CONTRIBUTING.md and CONDUCT.md for details.

Support

Bugs and feature request are tracked on GitHub.

If you have any questions about OAuth please open a ticket here; please don't email the address below.

Commercial Support

If you would like help implementing this library into your existing platform, or would be interested in OAuth advice or training for you and your team please get in touch with Glynde Labs.

Security

If you discover any security related issues, please email hello@alexbilbie.com instead of using the issue tracker.

License

This package is released under the MIT License. See the bundled LICENSE file for details.

Credits

This code is principally developed and maintained by Alex Bilbie.

Special thanks to all of these awesome contributors.

Additional thanks go to the Mozilla Secure Open Source Fund for funding a security audit of this library.

The initial code was developed as part of the Linkey project which was funded by JISC under the Access and Identity Management programme.