teknoo / east-common
Universal package, following the #East programming philosophy, build on Teknoo/East-Foundation (and Teknoo/Recipe), providing components (user management, object persistence, template rendering, ..) for the creation of web application or website.
Requires
- php: ^8.4
- php-di/php-di: ^7.1.1
- teknoo/east-foundation: ^9.2.4
- teknoo/immutable: ^3.0.22
- teknoo/recipe: ^7.3
- teknoo/states: ^7.1.11
Requires (Dev)
- ext-mongodb: *
- ext-tidy: *
- behat/behat: ^4.0
- behat/phpunit-assertions-extension: ^1.0
- doctrine/common: ^3.5
- doctrine/mongodb-odm: ^2.17.1
- doctrine/mongodb-odm-bundle: ^5.6
- doctrine/persistence: ^4.2
- guzzlehttp/promises: ^2.5.1||^3
- knpuniversity/oauth2-client-bundle: ^2.20.1
- laminas/laminas-diactoros: ^3.8
- league/flysystem: ^3.31
- league/flysystem-local: ^3.31
- league/mime-type-detection: ^1.16
- league/oauth2-client: ^2.9
- lexik/jwt-authentication-bundle: ^3.2
- matthiasmullie/minify: ^1.3.75
- phpstan/extension-installer: ^1.4.3
- phpstan/phpstan: ^2.2.12
- phpunit/phpunit: ^13.3.2
- roave/security-advisories: dev-latest
- scheb/2fa-backup-code: ^8.3
- scheb/2fa-bundle: ^8.3
- scheb/2fa-google-authenticator: ^8.3
- scheb/2fa-totp: ^8.3
- spomky-labs/otphp: ^11.4.2
- squizlabs/php_codesniffer: ^4.0.1
- symfony/cache: ^6.4.24||^7.4||^8.1
- symfony/cache-contracts: ^3.6
- symfony/clock: ^6.4.24||^7.4||^8.1
- symfony/config: ^6.4.24||^7.4||^8.1
- symfony/console: ^6.4.24||^7.4||^8.1
- symfony/dependency-injection: ^6.4.24||^7.4||^8.1
- symfony/error-handler: ^6.4.24||^7.4||^8.1
- symfony/event-dispatcher: ^6.4.24||^7.4||^8.1
- symfony/event-dispatcher-contracts: ^3.6
- symfony/expression-language: ^6.4.24||^7.4||^8.1
- symfony/filesystem: ^6.4.24||^7.4||^8.1
- symfony/form: ^6.4.24||^7.4||^8.1
- symfony/framework-bundle: ^6.4.24||^7.4||^8.1
- symfony/http-kernel: ^6.4.24||^7.4||^8.1
- symfony/mailer: ^6.4.24||^7.4||^8.1
- symfony/mime: ^6.4.24||^7.4||^8.1
- symfony/notifier: ^6.4.24||^7.4||^8.1
- symfony/password-hasher: ^6.4.24||^7.4||^8.1
- symfony/polyfill-php83: ^1.31
- symfony/property-access: ^6.4.24||^7.4||^8.1
- symfony/property-info: ^6.4.24||^7.4||^8.1
- symfony/psr-http-message-bridge: ^6.4.24||^7.4||^8.1
- symfony/routing: ^6.4.24||^7.4||^8.1
- symfony/security-bundle: ^6.4.24||^7.4||^8.1
- symfony/security-core: ^6.4.24||^7.4||^8.1
- symfony/security-http: ^6.4.24||^7.4||^8.1
- symfony/serializer: ^6.4.24||^7.4||^8.1
- symfony/string: ^6.4.24||^7.4||^8.1
- symfony/translation-contracts: ^3.6.1
- symfony/twig-bridge: ^6.4.24||^7.4||^8.1
- symfony/twig-bundle: ^6.4.24||^7.4||^8.1
- symfony/uid: ^6.4.24||^7.4||^8.1
- symfony/ux-live-component: ^2.32||^3
- symfony/ux-twig-component: ^2.32||^3
- symfony/validator: ^7.4||^8.1
- symfony/var-dumper: ^6.4.24||^7.4||^8.1
- symfony/yaml: ^6.4.24||^7.4||^8.1
- teknoo/bridge-phpdi-symfony: ^7.1.2
- twig/cssinliner-extra: ^3.23
- twig/inky-extra: ^3.23
- twig/twig: ^3.23
Suggests
- lexik/jwt-authentication-bundle: Required to create JWT tokens from API keys or from the web form (steps and endpoints `jwt.*`).
- symfony/serializer: Required to use the Twig filters to render JSON API responses (`east_api_*`).
- symfony/twig-bundle: Required to use the Twig filters and the templates shipped for JSON API responses.
- symfony/uid: Required when using the Doctrine ODM User mapping shipped by this library (UUID v7 id generation).
Provides
None
Conflicts
None
Replaces
None
- dev-master
- 4.6.1
- 4.6.0
- 4.5.1
- 4.5.0
- 4.4.1
- 4.4.0
- 4.3.0
- 4.2.3
- 4.2.2
- 4.2.1
- 4.2.0
- 4.1.5
- 4.1.4
- 4.1.3
- 4.1.2
- 4.1.1
- 4.1.0
- 4.0.3
- 4.0.2
- 4.0.1
- 4.0.0
- 3.5.4
- 3.5.3
- 3.5.2
- 3.5.1
- 3.5.0
- 3.4.0
- 3.3.0
- 3.2.0
- 3.1.0
- 3.0.8
- 3.0.7
- 3.0.6
- 3.0.5
- 3.0.4
- 3.0.3
- 3.0.2
- 3.0.1
- 3.0.0
- 2.13.0
- 2.12.6
- 2.12.5
- 2.12.4
- 2.12.3
- 2.12.2
- 2.12.1
- 2.12.0
- 2.11.0
- 2.10.1
- 2.10.0
- 2.9.3
- 2.9.2
- 2.9.1
- 2.9.0
- 2.8.0
- 2.7.3
- 2.7.2
- 2.7.1
- 2.7.0
- 2.6.6
- 2.6.5
- 2.6.4
- 2.6.3
- 2.6.2
- 2.6.1
- 2.6.0
- 2.5.1
- 2.5.0
- 2.4.0
- 2.4.0-beta2
- 2.4.0-beta1
- 2.3.2
- 2.3.1
- 2.3.0
- 2.2.0
- 2.1.0
- 2.0.1
- 2.0.0
- 2.0.0-beta1
- 1.9.6
- 1.9.5
- 1.9.4
- 1.9.3
- 1.9.2
- 1.9.1
- 1.9.0
- 1.8.2
- 1.8.1
- 1.8.0
- 1.7.1
- 1.7.0
- 1.6.2
- 1.6.1
- 1.6.0
- 1.5.0
- 1.4.7
- 1.4.6
- 1.4.5
- 1.4.4
- 1.4.3
- 1.4.2
- 1.4.1
- 1.4.0
- 1.3.0
- 1.2.6
- 1.2.5
- 1.2.4
- 1.2.3
- 1.2.2
- 1.2.1
- 1.2.0
- 1.1.0
- 1.0.4
- 1.0.3
- 1.0.2
- 1.0.1
- 1.0.0
- 1.0.0-beta2
- 1.0.0-beta1
- dev-release/v4
- dev-release/v3
This package is auto-updated.
Last update: 2026-10-08 07:59:09 UTC
README
Universal package, following the #East programming philosophy, build on Teknoo/East-Foundation (and Teknoo/Recipe), and providing components (user management, object persistence, template rendering, ..) for the creation of web application or website.
This project is a fork of East Website to separate the CMS (admin, front and translation) and all others base
components helpful to build a website or a webapp (objet persistence and CRUD operations, template rendering, user
management and authentification).
Example with Symfony
#These operations are not required with teknoo/east-common-symfony #config/packages/di_bridge.yaml: di_bridge: compilation_path: '%kernel.project_dir%/var/cache/phpdi' definitions: - '%kernel.project_dir%/config/di.php' #config/packages/east_foundation.yaml: di_bridge: definitions: - '%kernel.project_dir%/vendor/teknoo/east-foundation/src/di.php' - '%kernel.project_dir%/vendor/teknoo/east-foundation/infrastructures/symfony/config/di.php' - '%kernel.project_dir%/vendor/teknoo/east-foundation/infrastructures/symfony/config/laminas_di.php' import: Psr\Log\LoggerInterface: 'logger' #config/packages/east_common_di.yaml: di_bridge: definitions: - '%kernel.project_dir%/vendor/teknoo/east-common/src/di.php' - '%kernel.project_dir%/vendor/teknoo/east-common/infrastructures/doctrine/di.php' - '%kernel.project_dir%/vendor/teknoo/east-common/infrastructures/symfony/config/di.php' - '%kernel.project_dir%/vendor/teknoo/east-common/infrastructures/symfony/config/laminas_di.php' - '%kernel.project_dir%/vendor/teknoo/east-common/infrastructures/di.php' import: Doctrine\Persistence\ObjectManager: 'doctrine_mongodb.odm.default_document_manager' #bundles.php ... Teknoo\DI\SymfonyBridge\DIBridgeBundle::class => ['all' => true], Teknoo\East\FoundationBundle\EastFoundationBundle::class => ['all' => true], Teknoo\East\CommonBundle\TeknooEastCommonBundle::class => ['all' => true], #In doctrine config (east_common_doctrine_mongodb.yaml) doctrine_mongodb: document_managers: default: auto_mapping: true mappings: TeknooEastCommon: type: 'xml' dir: '%kernel.project_dir%/vendor/teknoo/east-common/infrastructures/doctrine/config/universal' is_bundle: false prefix: 'Teknoo\East\Common\Object' TeknooEastCommonDoctrine: type: 'xml' dir: '%kernel.project_dir%/vendor/teknoo/east-common/infrastructures/doctrine/config/doctrine' is_bundle: false prefix: 'Teknoo\East\Common\Doctrine\Object' #In security.yaml security: #... providers: with_password: id: 'Teknoo\East\CommonBundle\Provider\PasswordAuthenticatedUserProvider' password_hashers: Teknoo\East\CommonBundle\Object\PasswordAuthenticatedUser: algorithm: '%teknoo.east.common.bundle.password_authenticated_user_provider.default_algo%' #In routes/common.yaml admin_common: resource: '@TeknooEastCommonBundle/config/admin_routing.yaml' prefix: '/admin' common: resource: '@TeknooEastCommonBundle/config/routing.yaml'
Enable third party authentication with an OAuth2 Provider (example with Gitlab)
//In security.yaml security: providers: //... # Third party user provider from_third_party: id: 'Teknoo\East\CommonBundle\Provider\ThirdPartyAuthenticatedUserProvider' firewalls: # disables authentication for assets and the profiler, adapt it according to your needs //... admin_gitlab_login: pattern: '^/oauth2/gitlab/login$' security: false #require admin role for all others pages restricted_area: //... # Enable oauth2 authenticator for this form custom_authenticators: - '%teknoo.east.common.bundle.security.authenticator.oauth2.class%' //In knpu_oauth2_client.yaml knpu_oauth2_client: clients: # will create service: "knpu.oauth2.client.gitlab" # an instance of: KnpU\OAuth2ClientBundle\Client\Provider\GitlabClient # composer require omines/oauth2-gitlab gitlab: # must be "gitlab" - it activates that type! type: gitlab # add and set these environment variables in your .env files client_id: '%env(OAUTH_GITLAB_CLIENT_ID)%' client_secret: '%env(OAUTH_GITLAB_CLIENT_SECRET)%' # a route name you'll create redirect_route: admin_connect_gitlab_check redirect_params: {} # Base installation URL, modify this for self-hosted instances domain: '%env(OAUTH_GITLAB_URL)%' //In service.yaml services: Teknoo\East\CommonBundle\EndPoint\ConnectEndPoint: class: 'Teknoo\East\CommonBundle\EndPoint\ConnectEndPoint' arguments: - '@KnpU\OAuth2ClientBundle\Client\ClientRegistry' - 'gitlab' - ['read_user'] calls: - ['setResponseFactory', ['@Psr\Http\Message\ResponseFactoryInterface']] - ['setRouter', ['@router']] public: true Teknoo\East\CommonBundle\Contracts\Security\Authenticator\UserConverterInterface: class: 'App\Security\Authenticator\UserConverter'
//In src/Security\Authenticator\UserConverter.php <?php declare(strict_types=1); namespace App\Security\Authenticator; use DomainException; use League\OAuth2\Client\Provider\ResourceOwnerInterface; use Omines\OAuth2\Client\Provider\GitlabResourceOwner; use Teknoo\East\Common\Object\User; use Teknoo\East\CommonBundle\Contracts\Security\Authenticator\UserConverterInterface; use Teknoo\Recipe\Promise\PromiseInterface; class UserConverter implements UserConverterInterface { public function extractEmail(ResourceOwnerInterface $owner, PromiseInterface $promise): UserConverterInterface { if (!$owner instanceof GitlabResourceOwner) { $promise->fail(new DomainException('Resource not manager')); return $this; } $promise->success($owner->getEmail()); return $this; } public function convertToUser(ResourceOwnerInterface $owner, PromiseInterface $promise): UserConverterInterface { if (!$owner instanceof GitlabResourceOwner) { $promise->fail(new DomainException('Resource not manager')); return $this; } $promise->success( (new User())->setEmail($owner->getEmail()) ->setLastName($owner->getName()) ->setFirstName($owner->getUsername()) ); return $this; } }
//In routes/gitlab.yaml admin_connect_gitlab_login: path: '/oauth2/gitlab/login' defaults: _controller: 'Teknoo\East\CommonBundle\EndPoint\ConnectEndPoint' admin_connect_gitlab_check: path: '/oauth2/gitlab/check' defaults: _controller: 'teknoo.east.common.endpoint.static' template: '@@TeknooEastCommon/Admin/index.html.twig' errorTemplate: '@@TeknooEastCommon/Error/404.html.twig' _oauth_client_key: gitlab
//In your template, create a link with {{ path('admin_connect_gitlab_login') }}
Render JSON API responses
East Common's endpoints support JSON APIs. Add api: 'json' to a route's defaults, and use .json.twig templates
for template and errorTemplate. CSRF protection is disabled in this mode, and bodies can be sent as JSON (with the
header Content-Type: application/json), urlencoded or multipart. With a JSON body, the key publish publishes a
publishable object.
When symfony/serializer (enabled in framework.serializer) and symfony/twig-bundle (7.3 or later, the extensions
use Twig attributes) are installed, these Twig filters render JSON with the envelope {"meta": {...}, "data": ...}.
Objects are normalized by the East Foundation normalizer according to the groups passed in the context:
east_api_object_serialization(context, format, meta, parentObject): serializes an object or an array. The id and the root class of the identified object (or of the parent object) are added tometa.east_api_collection_serialization(page, pageCount, context, format, meta): serializes a paginated collection, withtotalPages,pageandcountinmeta.east_api_object_with_form_serialization(formView, context, format, meta, parentObject): serializes an object edited by a form, or, when the root form has errors (including errors bubbled from its fields), the form's errors, as{"meta": {"errors": true}, "data": {".field": "message"}}.east_api_error_serialization(format, meta): serializes an error, as{"meta": {"error": true}, "data": {"code": 404, "message": "..."}}. Previous errors are listed indata.previous, with their code and their message. The class, the file, the line and the trace of errors are never exported. Messages of server errors (5xx), previous errors included, are hidden unless the parameterteknoo.east.common.rendering.api.expose_server_error_messageis set totrue.- The function
east_api_form_errors(formView)returns all errors of a form, indexed by the field's path.
The bundle ships these templates, which applications can override in templates/bundles/TeknooEastCommonBundle/:
@TeknooEastCommon/Error/default.json.twig@TeknooEastCommon/api/AdminUser/{list,item,deleted}.json.twig@TeknooEastCommon/api/AdminMedia/{list,item,deleted}.json.twig
#In routes/api.yaml my_api_user_list: path: '/api/v1/admin/users' methods: ['GET'] defaults: _controller: 'teknoo.east.common.endpoint.crud.list' api: 'json' defaultOrderDirection: 'ASC' errorTemplate: '@@TeknooEastCommon/Error/default.json.twig' itemsPerPage: 20 loader: '@Teknoo\East\Common\Loader\UserLoader' template: '@@TeknooEastCommon/api/AdminUser/list.json.twig'
Authenticate API clients with API keys and JWT tokens
East Common can authenticate the clients of a JSON API with JWT tokens, thanks to
lexik/jwt-authentication-bundle. This bundle is not
required by East Common: install it (composer require lexik/jwt-authentication-bundle) only to use this feature.
A JWT token can be obtained in two ways:
- From an API key: a signed in user creates keys from a web page. An API client then logs in with a key, without the
user's password and without 2FA, on a
json_loginroute: the username iskey name:emailand the token is the secret of the key. The secret is displayed only once, when the key is created: only its hash is stored, in anApiKeyTokenowned by theApiKeysAuthof the user. A key has an expiration date. - From a web form, for a signed in user, or from the API, with a valid JWT token, to get a new one.
The json_login authenticator of Symfony ignores requests which are not in JSON, and the JWT authenticator then
answers 401 JWT Token not found. The login route shipped by East Common declares the format json, so the body of
the login request is read as JSON even when the client does not send the header Content-Type: application/json.
Authentication failures are rendered like other errors of a JSON API, as
{"meta": {"error": true}, "data": {"code": 401, "message": "..."}}: East Common listens to the failures dispatched by
lexik/jwt-authentication-bundle (JWT token not found, invalid or expired). To get the same response when a login
fails, set the failure handler of this bundle on the json_login authenticator, as below.
The lifetime of a JWT token is the expiration date asked in the form, limited to
teknoo.east.common.bundle.jwt.max_days_to_live days.
#In security.yaml security: providers: //... # API key user provider, the identifier is `key name:email` with_api_key: id: 'Teknoo\East\CommonBundle\Provider\ApiKeysAuthenticatedUserProvider' password_hashers: //... # Secrets of API keys are hashed like passwords Teknoo\East\CommonBundle\Object\ApiKeysAuthUser: algorithm: '%teknoo.east.common.bundle.password_authenticated_user_provider.default_algo%' firewalls: //... api_area: pattern: '^/api' stateless: true # Provider used to load the user of a JWT token, from its email provider: 'with_password' jwt: ~ json_login: provider: 'with_api_key' check_path: '_teknoo_common_api_jwt_login' username_path: 'username' password_path: 'token' # Render login failures like other errors of the API failure_handler: 'lexik_jwt_authentication.handler.authentication_failure' access_control: //... - { path: '^/api', roles: [IS_AUTHENTICATED_FULLY] } #In lexik_jwt_authentication.yaml lexik_jwt_authentication: secret_key: '%env(resolve:JWT_SECRET_KEY)%' public_key: '%env(resolve:JWT_PUBLIC_KEY)%' pass_phrase: '%env(JWT_PASSPHRASE)%' #In routes/common.yaml # Web pages to manage API keys and to generate a JWT token, in a firewall with a session api_keys_common: resource: '@TeknooEastCommonBundle/config/api_keys_routing.yaml' prefix: '/my-settings' jwt_common: resource: '@TeknooEastCommonBundle/config/jwt_routing.yaml' prefix: '/my-settings' # JSON API: `POST /api/v1/login`, the `check_path` of the `json_login` authenticator jwt_api_login_common: resource: '@TeknooEastCommonBundle/config/jwt_api_login_routing.yaml' prefix: '/api/v1' # JSON API: `POST /api/v1/jwt/create-token`, with a valid JWT token jwt_api_common: resource: '@TeknooEastCommonBundle/config/jwt_api_routing.yaml' prefix: '/api/v1' #In services.yaml parameters: # Prefix of generated secrets, empty by default teknoo.east.common.bundle.api_keys.token_prefix: 'my_' # Maximum lifetime of a JWT token, 1 day by default teknoo.east.common.bundle.jwt.max_days_to_live: 30
The JSON templates @TeknooEastCommon/api/Jwt/{token,form}.json.twig are shipped by the bundle: the token is returned
as {"meta": {"error": false}, "data": {"token": "..."}}. HTML templates of the web pages are provided by the
application, in templates/bundles/TeknooEastCommonBundle/User/:
api_keys.html.twig: form to create a key (formView, with the fieldsnameandexpiresAt) and list of keys.objectInstance.tokenis the secret of the key just created. Keys are available from the user, for example withapp.user.wrappedUser.getOneAuthData('Teknoo\\East\\Common\\Object\\ApiKeysAuth').tokens.jwt_form.html.twig: form to generate a JWT token (formView, with the fieldexpirationDate).jwt_token.html.twig: the generated token, injwtToken.
The application must also translate these keys: teknoo.east.common.api_keys.form.name,
teknoo.east.common.api_keys.form.name.regex_error, teknoo.east.common.api_keys.form.expiration,
teknoo.east.common.api_keys.error.already_exists, teknoo.east.common.api_keys.error.list_not_accessible and
teknoo.east.common.jwt.form.expiration.
With Doctrine ODM, the mapping of ApiKeysAuth and ApiKeyToken is shipped in
infrastructures/doctrine/config/universal, with the mapping of User.
Support this project
This project is free and will remain free. It is fully supported by commercial activities of SASU Teknoo Software and EIRL Richard DELOGE. If you like it and help me maintain it and evolve it, don't hesitate to support me on Patreon or Github.
Thanks :) Richard.
Credits
EIRL Richard Déloge - https://deloge.io - Lead developer. SASU Teknoo Software - https://teknoo.software
About Teknoo Software
Teknoo Software is a PHP software editor, founded by Richard Déloge, as part of EIRL Richard Déloge. Teknoo Software's goals : Provide to our partners and to the community a set of high quality services or software, sharing knowledge and skills.
License
East Common is licensed under the 3-Clause BSD License - see the licenses folder for details.
Installation & Requirements
To install this library with composer, run this command :
composer require teknoo/east-common
To start a project with Symfony :
symfony new your_project_name new
composer require teknoo/east-common-symfony
This library requires :
* PHP 8.1+
* A PHP autoloader (Composer is recommended)
* Teknoo/Immutable.
* Teknoo/States.
* Teknoo/Recipe.
* Teknoo/East-Foundation.
* Optional: Symfony 6.3+ (for administration)
News from Teknoo Common
This library requires PHP 8.1 or newer and it's only compatible with Symfony 6.0 or newer.
- Support Recipe 4.1.1+
- Support East Foundation 6.0.1+
- Public constant are final
- Block's types are Enums
- Direction are Enums
- Use readonly properties behaviors on Immutables
- Remove support of deprecated features removed in
Symfony 6.0(Salt,LegacyUser) - Use
(...)notation instead array notation for callable - Enable fiber support in front endpoint
QueryInterfacehas been splitted toQueryElementInterfaceandQueryCollectionInterfaceto differentiate queries fetching only one element, or a scalar value, and queries for collections of objects.LoaderInterface::querymethod is only dedicated forQueryCollectionInterfacequeries.- a new method
LoaderInterface::fetchis dedicated forQueryElementInterfacequeries.
- Warning * : All legacy user are not supported from this version. User's salt are also not supported, all users' passwords must be converted before switching to this version.
Contribute :)
You are welcome to contribute to this project. Fork it on Github