Override and extend Laravel's password reset to support OTP-style 6-digit tokens with verification state.
cndrsdrmn/passwords is a Laravel package for override and extend laravel's password reset to support otp-style 6-digit tokens with verification state..
It currently has 0 GitHub stars and 3 downloads on Packagist (latest version v1.1.0).
Install it with composer require cndrsdrmn/passwords.
Discover more Laravel packages by cndrsdrmn
or browse all Laravel packages to compare alternatives.
Last updated
A streamlined OTP password reset for your Laravel application. This package seamlessly integrates with the Password facade, so you can add a 6-digit OTP and a crucial verification step, managed by a new markVerified method, without changing your existing code. It just works.
You can install the package via Composer:
composer require cndrsdrmn/passwords
The service provider is auto-discovered. If you have disabled auto-discovery, you'll need to manually register it in your bootstrap/providers.php:
return [
// ...
Cndrsdrmn\Passwords\PasswordsServiceProvider::class,
],
After installation, run the migrations to create the necessary table:
php artisan migrate
You can optionally publish the migrations and translations if you need to customize them:
php artisan vendor:publish --tag=passwords-migrations
php artisan vendor:publish --tag=passwords-lang
This package uses the standard Laravel password configuration. You can find more details about configuring the password broker in the official Laravel documentation.
This package extends Laravel's default password broker by introducing a markVerified method. This adds an essential validation step before a password can be reset.
Before the user can reset their password, you must verify the OTP they provide. The package adds a new markVerified method to the broker, which you can call directly from the facade.
use Cndrsdrmn\Passwords\Contracts\OtpPasswordBroker as OtpBrokerContract;
use Illuminate\Support\Facades\Password;
$status = Password::markVerified([
'email' => $request->email,
'token' => $request->input('otp'),
]);
if ($status !== OtpBrokerContract::VERIFIED_TOKEN) {
return back()->withErrors(['token' => __($status)]);
}
For the rest of the password reset flow, you can follow the instructions in the official Laravel documentation.
This package is open-sourced software licensed under The MIT License (MIT). See the LICENSE file for more details.