wotz / socialite-zenith
Laravel Socialite provider for Zenith, the WOTZ OAuth2 server
Requires
- php: ^8.2
- illuminate/http: ^11.0|^12.0|^13.0
- illuminate/support: ^11.0|^12.0|^13.0
- laravel/socialite: ^5.5
Requires (Dev)
- laravel/pint: ^1.0
- orchestra/testbench: ^9.0|^10.0|^11.0
- pestphp/pest: ^3.0|^4.0
- pestphp/pest-plugin-laravel: ^3.0|^4.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
README
A Laravel Socialite provider for Zenith, the WOTZ OAuth2 server.
Zenith is a Laravel Passport server using the authorization code flow. This provider requests no scopes, so users don't see a consent screen.
Installation
composer require wotz/socialite-zenith
The service provider registers the zenith Socialite driver automatically.
Add the Zenith credentials to config/services.php:
'zenith' => [ 'base_url' => env('ZENITH_URL'), 'client_id' => env('ZENITH_CLIENT_ID'), 'client_secret' => env('ZENITH_CLIENT_SECRET'), 'redirect' => env('ZENITH_REDIRECT_URI'), ],
The client ID and secret come from a confidential client on Zenith. The redirect URI must match the one registered on that client exactly.
Usage
use Laravel\Socialite\Facades\Socialite; Route::get('/auth/zenith/redirect', fn () => Socialite::driver('zenith')->redirect()); Route::get('/auth/zenith/callback', function () { $zenithUser = Socialite::driver('zenith')->user(); $zenithUser->getId(); // Zenith user id, as a string $zenithUser->getName(); // "firstname lastname" $zenithUser->getEmail(); $zenithUser->getRaw(); // the full `data` object from /api/user/current });
To use it on a Filament panel, combine it with dutchcodingcompany/filament-socialite and register Provider::make('zenith') on the plugin.
Errors
The provider talks to Zenith through Laravel's HTTP client, so failures throw Illuminate\Http\Client\RequestException with the response attached. A user who is deactivated in Zenith gets a 403 from the user endpoint:
use Illuminate\Http\Client\RequestException; try { $zenithUser = Socialite::driver('zenith')->user(); } catch (RequestException $exception) { if ($exception->response->forbidden()) { // deactivated in Zenith } }
The access token
The access token works on the whole Zenith API for that user. Use it to fetch the user, then throw it away: don't store it, put it in the session or log it.
Testing
composer test
License
The MIT License (MIT). See LICENSE.md.