benbjurstrom / plink
Secure One-Time Passwords For Laravel
Fund package maintenance!
benbjurstrom
Requires
- php: ^8.2
- illuminate/contracts: ^10.0||^11.0
- spatie/laravel-package-tools: ^1.16
Requires (Dev)
- larastan/larastan: 2.9.8
- laravel/pint: ^1.14
- nunomaduro/collision: ^8.1.1||^7.10.0
- orchestra/testbench: ^9.0.0||^8.22.0
- pestphp/pest: ^2.34
- pestphp/pest-plugin-arch: ^2.7
- pestphp/pest-plugin-laravel: ^2.3
- phpstan/extension-installer: ^1.3
- phpstan/phpstan-deprecation-rules: ^1.1
- phpstan/phpstan-phpunit: ^1.3
This package is not auto-updated.
Last update: 2024-11-22 22:39:50 UTC
README
Passwordless Log-In Links for Laravel
This package provides full-featured passwordless log-in links for Laravel applications.
- ✅ Rate limited
- ✅ Invalidated after first use
- ✅ Locked to the user's session
- ✅ Configurable expiration
- ✅ Detailed error messages
- ✅ Customizable mail template
- ✅ Auditable logs
Installation
1. Install the package via composer
composer require benbjurstrom/plink
2. Add the package's interface and trait to your Authenticatable model
// app/Models/User.php namespace App\Models; //... use BenBjurstrom\Plink\Models\Concerns\HasPlinks; use BenBjurstrom\Plink\Models\Concerns\Plinkable; class User extends Authenticatable implements Plinkable { use HasFactory, Notifiable, HasPlinks; // ... }
3. Publish and run the migrations
php artisan vendor:publish --tag="plink-migrations"
php artisan migrate
4. Add the package provided routes
// routes/web.php Route::plinkRoutes();
5. (Optional) Publish the views for custom styling
php artisan vendor:publish --tag="plink-views"
This package publishes the following views:
resources/ └── views/ └── vendor/ └── plink/ ├── error.blade.php └── mail/ └── plink.blade.php
6. (Optional) Publish the config file
php artisan vendor:publish --tag="plink-config"
This is the contents of the published config file:
<?php return [ /* |-------------------------------------------------------------------------- | Model Configuration |-------------------------------------------------------------------------- | | This setting determines the model used by Plink to store and retrieve | one-time passwords. By default, it uses the 'App\Models\User' model. | */ 'models' => [ 'authenticatable' => env('AUTH_MODEL', App\Models\User::class), ], ];
Usage
- Replace the Laravel Breeze LoginForm authenticate method with a sendEmail method that runs the SendPlink action. For example:
public function sendEmail(): void { $this->validate(); $this->ensureIsNotRateLimited(); RateLimiter::hit($this->throttleKey(), 300); try { (new SendPlink)->handle($this->email); } catch (PlinkThrottleException $e) { throw ValidationException::withMessages([ 'form.email' => $e->getMessage(), ]); } RateLimiter::clear($this->throttleKey()); }
Everything else is handled by the package components.
Testing
composer test
Changelog
Please see CHANGELOG for more information on what has changed recently.
Contributing
Please see CONTRIBUTING for details.
Security Vulnerabilities
Please review our security policy on how to report security vulnerabilities.
Credits
License
The MIT License (MIT). Please see License File for more information.