Custom Request Grant for Laravel Passport
mikemclin/passport-custom-request-grant is a Laravel package for custom request grant for laravel passport.
It currently has 34 GitHub stars and 3.698 downloads on Packagist (latest version 1.0.1).
Install it with composer require mikemclin/passport-custom-request-grant.
Discover more Laravel packages by mikemclin
or browse all Laravel packages to compare alternatives.
Last updated
Install with composer... composer require mikemclin/passport-custom-request-grant
^1.0^0.1MikeMcLin\Passport\CustomRequestGrantProvider to your list of providers after Laravel\Passport\PassportServiceProvider.byPassportCustomRequest($request) method to your User model (or whatever model you have configured to work with Passport).
Illuminate\Http\Request object.nullhttps://your-site.com/oauth/token, just like you would a Password or Refresh grant.grant_type = custom_request.User::byPassportCustomRequest() function, where you will determine if access should be granted or not.access_token and refresh_token will be returned if successful.Here is what a User::byPassportCustomRequest() method might look like...
/**
* Verify and retrieve user by custom token request.
*
* @param \Illuminate\Http\Request $request
*
* @return \Illuminate\Database\Eloquent\Model|null
* @throws \League\OAuth2\Server\Exception\OAuthServerException
*/
public function byPassportCustomRequest(Request $request)
{
try {
if ($request->get('sso_token')) {
return $this->bySsoToken($request->get('sso_token'));
}
} catch (\Exception $e) {
throw OAuthServerException::accessDenied($e->getMessage());
}
return null;
}
In this example, the app is able to authenticate a user based on an sso_token property from a submitted JSON payload. The bySsoToken is this app's way of doing that. It will return null or a user object. It also might throw exceptions explaining why the token is invalid. The byPassportCustomRequest catches any of those exceptions and converts them to appropriate OAuth exception type. If an ssoToken is not present on the request payload, then we return null which returns an invalid_credentials error response:
{
"error": "invalid_credentials",
"message": "The user credentials were incorrect."
}