jeffersongoncalves / filament-sso-client
Filament panel integration for laravel-sso-client: SSO login page, forced IdP redirect and federated logout.
Package info
github.com/jeffersongoncalves/filament-sso-client
pkg:composer/jeffersongoncalves/filament-sso-client
Requires
- php: ^8.2
- filament/filament: ^5.0
- jeffersongoncalves/laravel-sso-client: ^1.1
- spatie/laravel-package-tools: ^1.16
Requires (Dev)
- larastan/larastan: ^2.0|^3.0
- laravel/pint: ^1.0
- orchestra/testbench: ^10.0|^11.0
- pestphp/pest: ^3.0|^4.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
README
Filament SSO Client
Filament panel integration for jeffersongoncalves/laravel-sso-client: a "Sign in with SSO" button on the panel login page (or a direct redirect to the SSO Server), federated logout from the user menu and Single Logout enforcement on every panel request.
Compatibility
| Package Version | Filament Version |
|---|---|
| 1.x | 3.x |
| 2.x | 4.x |
| 3.x | 5.x |
Requires laravel-sso-client 1.1+ (federated logout).
Installation
You can install the package via composer:
composer require jeffersongoncalves/filament-sso-client
Then configure laravel-sso-client as described in its README (server credentials, sso_id migration).
The panel and the SSO callback must log users into the same guard: keep sso-client.guard equal to the panel's authGuard() (both default to the app's default guard).
Usage
Register the plugin in your PanelProvider:
use JeffersonGoncalves\Filament\SsoClient\SsoClientPlugin; public function panel(Panel $panel): Panel { return $panel ->default() ->id('admin') ->path('admin') ->plugins([ SsoClientPlugin::make(), ]); }
The plugin:
- replaces the panel login page with one that shows a Sign in with SSO button under the local email/password form;
- points the user menu logout item at
POST /sso/logout, which ends the local session, the SSO session and the user's other client apps; - adds a panel auth middleware that ends sessions revoked by Single Logout (the
sso.authcheck, for signed-in users only).
Filament's own Authenticate middleware stays in place, so canAccessPanel() is still enforced for SSO users.
SSO only (redirect straight to the SSO Server)
SsoClientPlugin::make() ->forceRedirect(),
Guests that open the panel go directly to the SSO Server and come back to the page they asked for.
SSO button only (no local form)
SsoClientPlugin::make() ->loginForm(false),
The login page only shows the SSO button, and local credentials are refused.
Button label
SsoClientPlugin::make() ->buttonLabel('Sign in with your corporate account'),
The default label is translated (en, pt_BR); publish the translations with php artisan vendor:publish --tag="filament-sso-client-translations".
Testing
composer test
Changelog
Please see CHANGELOG for more information on what has changed recently.
Security
If you discover any security related issues, please email the author instead of using the issue tracker.
Credits
License
The MIT License (MIT). Please see License File for more information.
