componenta / auth-token
Purpose-separated one-time bearer tokens for Componenta authentication flows
v1.0.0
2026-09-27 22:32 UTC
Requires
- php: ^8.4
- componenta/identity: ^1.0.1
- cycle/database: ^2.22
- psr/clock: ^1.0
Requires (Dev)
- componenta/clock: ^1.1.0
- phpstan/phpstan: ^2.1
- phpunit/phpunit: ^12.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-27 22:46:15 UTC
README
Purpose-separated, single-use bearer tokens for authentication flows.
The package is a reusable primitive for magic links, password reset and similar one-time flows. It deliberately keeps one active token per subject and purpose.
Security properties:
- credentials contain 32 CSPRNG bytes encoded as unpadded base64url;
- raw credentials are never persisted;
- persisted lookup values are SHA-256 hashes domain-separated by purpose;
- replacement is atomic on the unique
(subject_uuid, purpose)key; - consumption is atomic and single-use;
- purpose is part of lookup/consume, so a token issued for one flow cannot be accepted by another flow.