php-jwt | Laravel | |
---|---|---|
16 | 225 | |
9,228 | 31,520 | |
0.3% | 0.5% | |
5.8 | 10.0 | |
about 1 month ago | 3 days ago | |
PHP | PHP | |
BSD 3-clause "New" or "Revised" License | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
php-jwt
- firebase/php-jwt: PHP package for JWT
-
Understanding user authentication on web and API
So basically if the login is successfull I have to create a JWT token (with something like this library) with the userID inside and send it via `setcookie()` for web or in a JSON response to the API client and consider it the long lived refresh token.
-
What is the best way to implement in-app purchases without a third-party service?
This depends on the library you end up downloading for the platform of your choosing. Some of the parts I explained above will be handled by the library for example in my case I decoded signedTransactionInfo using firebase/php-jwt. This has the added benefit of always checking the validity of the signature which was omitted in the manual method.
- Why there's not a native way to work with JWT in Laravel?
-
How can I decode the header from the JWT?
https://github.com/firebase/php-jwt i use this one, its really good
- ElastiCache for Redis as session handler for ECS container...
- Weekly "ask anything" thread
-
API Tokens: A Tedious Survey
> Why all the hate for JWTs?
> Just pick a crypto scheme and the JWT is just an encoding that makes it easier to use.
That's not what JWT is, but I can understand why someone would be misled into believing that.
JWT isn't just an encoding format, it also includes a crypto algorithm negotiation protocol that lets the attacker choose the algorithm. Even if you strictly allow-list which algorithm you want to support, you can accidentally bypass this control in many libraries if you suppor the `kid` (key ID) header. [1]
It also allows attackers to completely strip the security. [2] [3]
Put shortly, JWT is a gun aimed directly at your foot. That's why there's so much hate for JWTs.
[1] https://github.com/firebase/php-jwt/issues/351
[2] https://paragonie.com/blog/2017/03/jwt-json-web-tokens-is-ba...
[3] https://www.howmanydayssinceajwtalgnonevuln.com/
- Firebase/PHP-JWT: New Risk of HS256/RSA256 Algorithm Confusion
- Possible security issue involving the Firebase JWT library for PHP (Algorithm Confusion with Key IDs)
Laravel
-
Tell HN: Laravel's default truncate method uses cascade for Postgres databases
Hope this saves a future team from unexpected behavior resulting in (potential) production data loss.
When using Postgres, Laravel's default method for truncate uses the cascade option, which will ignore foreign key constraints and potentially wipe large amounts of data with no confirmation or warning.
It was originally introduced in 2018: https://github.com/laravel/framework/pull/26389/files
Here are two threads on it if you are curious: https://github.com/laravel/framework/issues/29506
-
Exploring Middleware in Laravel 11
I am just exploring middleware in this post, but as you can see this is quite a different approach than we've seen historically. I sat there scratching my head, "How do I set up my own middleware? How do I change the defaults?" I had to explore the Illuminate\Foundation\Configuration\Middleware class to find out.
- Automatizando fluxos de trabalho com GitHub Actions
- Testando filas em projetos Laravel
-
alof-lib: a PHP array-like objects functions library
For example check out this issue I reported on their side: https://github.com/laravel/framework/issues/49089
-
PHP: check dates
It does not mean you should absolutely use it everywhere, but it can make sense for your case. Many frameworks, like Laravel use it to compose new projects.
-
An Internet of PHP
https://github.com/laravel/framework/blob/00894b89e42a9d707c...
Even Tinker is a few lines of code to extend PsySH and credit is barely given.
Taylor Otwell is a fiend for creating wrappers around solid open source libraries, using PHP magic and encouraging bad practices, all just to breed an ecosystem ultimately to land him a Lambo, fuelled by amazing open source foundations that have barely been contributed back to by him.
- Laravel 10.15 Released: Sub-minute Task Scheduling, Raw SQL Query Builder Methods, and More
-
Laravel’s ForwardsCalls trait
This same system has been used in Laravel since version 4.0* albeit in the more PHP plain way, using call_user_func_array (Laravel Model Class).
- From Concept to Image: Exploring OpenAI Image Generation API with Laravel 10 and VueJS
What are some alternatives?
PHP OAuth 2.0 Server - A spec compliant, secure by default PHP OAuth 2.0 Server
nuxt3-supabase - Nuxt 3 module and composables for Supabase.
Ratchet - Asynchronous WebSocket server
octane - Supercharge your Laravel application's performance.
Fast Route - Fast request router for PHP
fingerprintjs - Browser fingerprinting library. Accuracy of this version is 40-60%, accuracy of the commercial Fingerprint Identification is 99.5%. V4 of this library is BSL licensed.
fusionauth-jwt - A simple to use Java 8 JWT Library. Verify, Sign, Encode, Decode all day.
FrameworkBenchmarks - Source for the TechEmpower Framework Benchmarks project
paseto - Platform-Agnostic Security Tokens
Nextcloud - ☁️ Nextcloud server, a safe home for all your data
Halite - High-level cryptography interface powered by libsodium
ProxiTok - Open source alternative frontend for TikTok made using PHP