feat: JWT Authenticator - #195

Merged
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt
Apr 21, 2023
Merged

feat: JWT Authenticator#195
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt

Conversation

@kenjis

@kenjiskenjis commented Jun 1, 2022

Copy link
Copy Markdown
Member

Needs #703
Needs to rebase after merging #194, #199

Add:

  • Config\AuthJWT
  • Authentication\Authenticators\JWT
  • Filters\JWTAuth
  • Authentication\JWTManager = service((jwtmanager)

How to Test/Use:

Sample Test App:

TODO:

  • login recording specification
  • update docs

@kenjis
kenjis marked this pull request as draft June 1, 2022 07:52

@MGatnerMGatner left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking awesome! I had no idea you were working on this, I would have guessed version 1.1 or 1.2.

Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Config/Auth.php Outdated

@lonnieezelllonnieezell left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's great to see a JWT implementation coming! Thanks for this.

However, I do have a couple of concerns with the current implementation.

  1. Choice of implementation. Why choose Firebase's implementation? I think the best reason is probably that it's backed by Google, but according to the the JWT site, it doesn't provide the most complete implementation. That might not be all bad, though. Honestly, I kind of had it in mind that if we ever included JWT we'd roll our own since the implementation of a JWT is pretty straight-forward. Not sure if that's worth considering to remove the reliance on a third-party libs changes, etc.

  2. I think you may have over-architected it. I've commented on a few classes along the way, but in general I think we should strive for as simple of an architecture as the library allows.

This would also require updating all docs and adding new docs.

I don't think we'll be able to get this one in before the initial release.

Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/JWTDecoderInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWT/JWTGeneratorInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWTGenerator.php Outdated
Comment threadsrc/Config/Auth.php Outdated
@kenjis

Copy link
Copy Markdown
MemberAuthor

I don't think we'll be able to get this one in before the initial release.

There are some parts of this feature that require consideration of specifications.
I think it will take some time.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Why choose Firebase's implementation?

I googled CodeIgniter4 jwt, and found most tutorials use Firebase implementation.
And it is commonly used in my country. So first of all, I chose it.

But I know it doesn't provide the most complete implementation, so I made it replaceable.

@datamweb

Copy link
Copy Markdown
Collaborator

It is also commonly used in my country.

@kenjis
kenjisforce-pushed the feat-jwt branch 4 times, most recently from 443000b to 0a0920eCompareJune 3, 2022 05:22
@kenjiskenjis added the new feature PRs for new features label Aug 8, 2022
Comment threadsrc/Filters/JWTAuth.php Outdated
@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 7c2720f to a85c422CompareOctober 21, 2022 08:31
@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

I don't remember much of the implementation as a lot of time has passed, but I think the implementation itself was done in one way or another.

If there is someone who wants to try JWT, please test. Of course code reviews are also welcome.
I am going to run the code and see if this really works.

@MGatner

Copy link
Copy Markdown
Member

My only JWT CI4 project currently uses Myth and I've had issues installing Shield alongside because they have some conflicting services and factories. I know some community members have been keen on this - maybe check the forums for volunteers?

@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

Good idea! I've posted the forum.

@hainm0912

Copy link
Copy Markdown

it finished? how to use this branch?

@kenjis

Copy link
Copy Markdown
MemberAuthor

This should work. You can get the code from my repository:
https://github.com/kenjis/codeigniter-shield/tree/feat-jwt

@kenjis

Copy link
Copy Markdown
MemberAuthor

how to use this branch?

Update your composer.json:

--- a/composer.json+++ b/composer.json@@ -7,7 +7,8 @@
"require": {
"php": "^7.4 || ^8.0",
"codeigniter4/framework": "^4.0",
- "codeigniter4/shield": "^1.0@beta"+ "codeigniter4/shield": "dev-feat-jwt",+ "firebase/php-jwt": "^6.2"
},
"require-dev": {
"fakerphp/faker": "^1.9",
@@ -36,5 +37,11 @@
"slack": "https://codeigniterchat.slack.com"
},
"minimum-stability": "dev",
- "prefer-stable": true+ "prefer-stable": true,+ "repositories": [+ {+ "type": "vcs",+ "url": "https://github.com/kenjis/codeigniter-shield.git"+ }+ ]
}

Run composer update.

@ghost

Copy link
Copy Markdown

What is the status on JWT authentication?

Any TODOs I could help with?

@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 58f6d62 to 324bcb7CompareApril 13, 2023 23:43
@kenjis

Copy link
Copy Markdown
MemberAuthor

Rebased to resolve conflicts.

@kenjis

Copy link
Copy Markdown
MemberAuthor

What is the status on JWT authentication?

The implementation was finished. I need to write docs.

Any TODOs I could help with?

Testing and review. As you see, no one has approved this PR yet.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner@datamweb Can you review?

@datamweb

Copy link
Copy Markdown
Collaborator

@kenjis will try to do today.

Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threadsrc/Authentication/JWTManager.php
Comment threadsrc/Config/Auth.php Outdated
Comment threadsrc/Config/AuthJWT.php
Comment threadsrc/Language/fa/Auth.php Outdated
@datamweb

Copy link
Copy Markdown
Collaborator

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)

And the next question is there a way to expire the token for a specific user?

Please update the README file, the reference to support JWT is good.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)
And the next question is there a way to expire the token for a specific user?

Tokens are to be validated by defining the conditions that make it invalid.

If you want to invalidate tokens to a specific user, you can do it by specifying the user ID and issued at.

Also, as you say, If you change the key, all tokens signed with that key will be invalidated.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, thanks, everything seems to be working fine now.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@datamweb Thank you for the detailed review!

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner Can you approve? Without your approve, I cannot merge this.

kenjis added a commit to kenjis/codeigniter-shield that referenced this pull request Apr 21, 2023
There is no need to change the status code since a validation error is still an authentication failure.
See codeigniter4#195 (comment)
@kenjis
kenjis merged commit 392bd48 into codeigniter4:developApr 21, 2023
@kenjis
kenjis deleted the feat-jwt branch April 21, 2023 12:26
@kenjis

Copy link
Copy Markdown
MemberAuthor

Thank you all!

@kenjiskenjis mentioned this pull request Apr 22, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 25, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 30, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@kenjis@datamweb@MGatner@hainm0912@lonnieezell@michalsn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat: JWT Authenticator - #195

Merged
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt
Apr 21, 2023
Merged

feat: JWT Authenticator#195
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt

Conversation

@kenjis

@kenjiskenjis commented Jun 1, 2022

Copy link
Copy Markdown
Member

Needs #703
Needs to rebase after merging #194, #199

Add:

  • Config\AuthJWT
  • Authentication\Authenticators\JWT
  • Filters\JWTAuth
  • Authentication\JWTManager = service((jwtmanager)

How to Test/Use:

Sample Test App:

TODO:

  • login recording specification
  • update docs

@kenjis
kenjis marked this pull request as draft June 1, 2022 07:52

@MGatnerMGatner left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking awesome! I had no idea you were working on this, I would have guessed version 1.1 or 1.2.

Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Config/Auth.php Outdated

@lonnieezelllonnieezell left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's great to see a JWT implementation coming! Thanks for this.

However, I do have a couple of concerns with the current implementation.

  1. Choice of implementation. Why choose Firebase's implementation? I think the best reason is probably that it's backed by Google, but according to the the JWT site, it doesn't provide the most complete implementation. That might not be all bad, though. Honestly, I kind of had it in mind that if we ever included JWT we'd roll our own since the implementation of a JWT is pretty straight-forward. Not sure if that's worth considering to remove the reliance on a third-party libs changes, etc.

  2. I think you may have over-architected it. I've commented on a few classes along the way, but in general I think we should strive for as simple of an architecture as the library allows.

This would also require updating all docs and adding new docs.

I don't think we'll be able to get this one in before the initial release.

Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/JWTDecoderInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWT/JWTGeneratorInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWTGenerator.php Outdated
Comment threadsrc/Config/Auth.php Outdated
@kenjis

Copy link
Copy Markdown
MemberAuthor

I don't think we'll be able to get this one in before the initial release.

There are some parts of this feature that require consideration of specifications.
I think it will take some time.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Why choose Firebase's implementation?

I googled CodeIgniter4 jwt, and found most tutorials use Firebase implementation.
And it is commonly used in my country. So first of all, I chose it.

But I know it doesn't provide the most complete implementation, so I made it replaceable.

@datamweb

Copy link
Copy Markdown
Collaborator

It is also commonly used in my country.

@kenjis
kenjisforce-pushed the feat-jwt branch 4 times, most recently from 443000b to 0a0920eCompareJune 3, 2022 05:22
@kenjiskenjis added the new feature PRs for new features label Aug 8, 2022
Comment threadsrc/Filters/JWTAuth.php Outdated
@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 7c2720f to a85c422CompareOctober 21, 2022 08:31
@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

I don't remember much of the implementation as a lot of time has passed, but I think the implementation itself was done in one way or another.

If there is someone who wants to try JWT, please test. Of course code reviews are also welcome.
I am going to run the code and see if this really works.

@MGatner

Copy link
Copy Markdown
Member

My only JWT CI4 project currently uses Myth and I've had issues installing Shield alongside because they have some conflicting services and factories. I know some community members have been keen on this - maybe check the forums for volunteers?

@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

Good idea! I've posted the forum.

@hainm0912

Copy link
Copy Markdown

it finished? how to use this branch?

@kenjis

Copy link
Copy Markdown
MemberAuthor

This should work. You can get the code from my repository:
https://github.com/kenjis/codeigniter-shield/tree/feat-jwt

@kenjis

Copy link
Copy Markdown
MemberAuthor

how to use this branch?

Update your composer.json:

--- a/composer.json+++ b/composer.json@@ -7,7 +7,8 @@
"require": {
"php": "^7.4 || ^8.0",
"codeigniter4/framework": "^4.0",
- "codeigniter4/shield": "^1.0@beta"+ "codeigniter4/shield": "dev-feat-jwt",+ "firebase/php-jwt": "^6.2"
},
"require-dev": {
"fakerphp/faker": "^1.9",
@@ -36,5 +37,11 @@
"slack": "https://codeigniterchat.slack.com"
},
"minimum-stability": "dev",
- "prefer-stable": true+ "prefer-stable": true,+ "repositories": [+ {+ "type": "vcs",+ "url": "https://github.com/kenjis/codeigniter-shield.git"+ }+ ]
}

Run composer update.

@ghost

Copy link
Copy Markdown

What is the status on JWT authentication?

Any TODOs I could help with?

@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 58f6d62 to 324bcb7CompareApril 13, 2023 23:43
@kenjis

Copy link
Copy Markdown
MemberAuthor

Rebased to resolve conflicts.

@kenjis

Copy link
Copy Markdown
MemberAuthor

What is the status on JWT authentication?

The implementation was finished. I need to write docs.

Any TODOs I could help with?

Testing and review. As you see, no one has approved this PR yet.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner@datamweb Can you review?

@datamweb

Copy link
Copy Markdown
Collaborator

@kenjis will try to do today.

Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threadsrc/Authentication/JWTManager.php
Comment threadsrc/Config/Auth.php Outdated
Comment threadsrc/Config/AuthJWT.php
Comment threadsrc/Language/fa/Auth.php Outdated
@datamweb

Copy link
Copy Markdown
Collaborator

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)

And the next question is there a way to expire the token for a specific user?

Please update the README file, the reference to support JWT is good.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)
And the next question is there a way to expire the token for a specific user?

Tokens are to be validated by defining the conditions that make it invalid.

If you want to invalidate tokens to a specific user, you can do it by specifying the user ID and issued at.

Also, as you say, If you change the key, all tokens signed with that key will be invalidated.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, thanks, everything seems to be working fine now.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@datamweb Thank you for the detailed review!

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner Can you approve? Without your approve, I cannot merge this.

kenjis added a commit to kenjis/codeigniter-shield that referenced this pull request Apr 21, 2023
There is no need to change the status code since a validation error is still an authentication failure.
See codeigniter4#195 (comment)
@kenjis
kenjis merged commit 392bd48 into codeigniter4:developApr 21, 2023
@kenjis
kenjis deleted the feat-jwt branch April 21, 2023 12:26
@kenjis

Copy link
Copy Markdown
MemberAuthor

Thank you all!

@kenjiskenjis mentioned this pull request Apr 22, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 25, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 30, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@kenjis@datamweb@MGatner@hainm0912@lonnieezell@michalsn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: JWT Authenticator - #195

Merged
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt
Apr 21, 2023
Merged

feat: JWT Authenticator#195
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt

Conversation

@kenjis

@kenjiskenjis commented Jun 1, 2022

Copy link
Copy Markdown
Member

Needs #703
Needs to rebase after merging #194, #199

Add:

  • Config\AuthJWT
  • Authentication\Authenticators\JWT
  • Filters\JWTAuth
  • Authentication\JWTManager = service((jwtmanager)

How to Test/Use:

Sample Test App:

TODO:

  • login recording specification
  • update docs

@kenjis
kenjis marked this pull request as draft June 1, 2022 07:52

@MGatnerMGatner left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking awesome! I had no idea you were working on this, I would have guessed version 1.1 or 1.2.

Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Config/Auth.php Outdated

@lonnieezelllonnieezell left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's great to see a JWT implementation coming! Thanks for this.

However, I do have a couple of concerns with the current implementation.

  1. Choice of implementation. Why choose Firebase's implementation? I think the best reason is probably that it's backed by Google, but according to the the JWT site, it doesn't provide the most complete implementation. That might not be all bad, though. Honestly, I kind of had it in mind that if we ever included JWT we'd roll our own since the implementation of a JWT is pretty straight-forward. Not sure if that's worth considering to remove the reliance on a third-party libs changes, etc.

  2. I think you may have over-architected it. I've commented on a few classes along the way, but in general I think we should strive for as simple of an architecture as the library allows.

This would also require updating all docs and adding new docs.

I don't think we'll be able to get this one in before the initial release.

Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/JWTDecoderInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWT/JWTGeneratorInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWTGenerator.php Outdated
Comment threadsrc/Config/Auth.php Outdated
@kenjis

Copy link
Copy Markdown
MemberAuthor

I don't think we'll be able to get this one in before the initial release.

There are some parts of this feature that require consideration of specifications.
I think it will take some time.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Why choose Firebase's implementation?

I googled CodeIgniter4 jwt, and found most tutorials use Firebase implementation.
And it is commonly used in my country. So first of all, I chose it.

But I know it doesn't provide the most complete implementation, so I made it replaceable.

@datamweb

Copy link
Copy Markdown
Collaborator

It is also commonly used in my country.

@kenjis
kenjisforce-pushed the feat-jwt branch 4 times, most recently from 443000b to 0a0920eCompareJune 3, 2022 05:22
@kenjiskenjis added the new feature PRs for new features label Aug 8, 2022
Comment threadsrc/Filters/JWTAuth.php Outdated
@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 7c2720f to a85c422CompareOctober 21, 2022 08:31
@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

I don't remember much of the implementation as a lot of time has passed, but I think the implementation itself was done in one way or another.

If there is someone who wants to try JWT, please test. Of course code reviews are also welcome.
I am going to run the code and see if this really works.

@MGatner

Copy link
Copy Markdown
Member

My only JWT CI4 project currently uses Myth and I've had issues installing Shield alongside because they have some conflicting services and factories. I know some community members have been keen on this - maybe check the forums for volunteers?

@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

Good idea! I've posted the forum.

@hainm0912

Copy link
Copy Markdown

it finished? how to use this branch?

@kenjis

Copy link
Copy Markdown
MemberAuthor

This should work. You can get the code from my repository:
https://github.com/kenjis/codeigniter-shield/tree/feat-jwt

@kenjis

Copy link
Copy Markdown
MemberAuthor

how to use this branch?

Update your composer.json:

--- a/composer.json+++ b/composer.json@@ -7,7 +7,8 @@
"require": {
"php": "^7.4 || ^8.0",
"codeigniter4/framework": "^4.0",
- "codeigniter4/shield": "^1.0@beta"+ "codeigniter4/shield": "dev-feat-jwt",+ "firebase/php-jwt": "^6.2"
},
"require-dev": {
"fakerphp/faker": "^1.9",
@@ -36,5 +37,11 @@
"slack": "https://codeigniterchat.slack.com"
},
"minimum-stability": "dev",
- "prefer-stable": true+ "prefer-stable": true,+ "repositories": [+ {+ "type": "vcs",+ "url": "https://github.com/kenjis/codeigniter-shield.git"+ }+ ]
}

Run composer update.

@ghost

Copy link
Copy Markdown

What is the status on JWT authentication?

Any TODOs I could help with?

@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 58f6d62 to 324bcb7CompareApril 13, 2023 23:43
@kenjis

Copy link
Copy Markdown
MemberAuthor

Rebased to resolve conflicts.

@kenjis

Copy link
Copy Markdown
MemberAuthor

What is the status on JWT authentication?

The implementation was finished. I need to write docs.

Any TODOs I could help with?

Testing and review. As you see, no one has approved this PR yet.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner@datamweb Can you review?

@datamweb

Copy link
Copy Markdown
Collaborator

@kenjis will try to do today.

Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threadsrc/Authentication/JWTManager.php
Comment threadsrc/Config/Auth.php Outdated
Comment threadsrc/Config/AuthJWT.php
Comment threadsrc/Language/fa/Auth.php Outdated
@datamweb

Copy link
Copy Markdown
Collaborator

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)

And the next question is there a way to expire the token for a specific user?

Please update the README file, the reference to support JWT is good.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)
And the next question is there a way to expire the token for a specific user?

Tokens are to be validated by defining the conditions that make it invalid.

If you want to invalidate tokens to a specific user, you can do it by specifying the user ID and issued at.

Also, as you say, If you change the key, all tokens signed with that key will be invalidated.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, thanks, everything seems to be working fine now.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@datamweb Thank you for the detailed review!

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner Can you approve? Without your approve, I cannot merge this.

kenjis added a commit to kenjis/codeigniter-shield that referenced this pull request Apr 21, 2023
There is no need to change the status code since a validation error is still an authentication failure.
See codeigniter4#195 (comment)
@kenjis
kenjis merged commit 392bd48 into codeigniter4:developApr 21, 2023
@kenjis
kenjis deleted the feat-jwt branch April 21, 2023 12:26
@kenjis

Copy link
Copy Markdown
MemberAuthor

Thank you all!

@kenjiskenjis mentioned this pull request Apr 22, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 25, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 30, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@kenjis@datamweb@MGatner@hainm0912@lonnieezell@michalsn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: JWT Authenticator - #195

Merged
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt
Apr 21, 2023
Merged

feat: JWT Authenticator#195
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt

Conversation

@kenjis

@kenjiskenjis commented Jun 1, 2022

Copy link
Copy Markdown
Member

Needs #703
Needs to rebase after merging #194, #199

Add:

  • Config\AuthJWT
  • Authentication\Authenticators\JWT
  • Filters\JWTAuth
  • Authentication\JWTManager = service((jwtmanager)

How to Test/Use:

Sample Test App:

TODO:

  • login recording specification
  • update docs

@kenjis
kenjis marked this pull request as draft June 1, 2022 07:52

@MGatnerMGatner left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking awesome! I had no idea you were working on this, I would have guessed version 1.1 or 1.2.

Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Config/Auth.php Outdated

@lonnieezelllonnieezell left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's great to see a JWT implementation coming! Thanks for this.

However, I do have a couple of concerns with the current implementation.

  1. Choice of implementation. Why choose Firebase's implementation? I think the best reason is probably that it's backed by Google, but according to the the JWT site, it doesn't provide the most complete implementation. That might not be all bad, though. Honestly, I kind of had it in mind that if we ever included JWT we'd roll our own since the implementation of a JWT is pretty straight-forward. Not sure if that's worth considering to remove the reliance on a third-party libs changes, etc.

  2. I think you may have over-architected it. I've commented on a few classes along the way, but in general I think we should strive for as simple of an architecture as the library allows.

This would also require updating all docs and adding new docs.

I don't think we'll be able to get this one in before the initial release.

Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/JWTDecoderInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWT/JWTGeneratorInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWTGenerator.php Outdated
Comment threadsrc/Config/Auth.php Outdated
@kenjis

Copy link
Copy Markdown
MemberAuthor

I don't think we'll be able to get this one in before the initial release.

There are some parts of this feature that require consideration of specifications.
I think it will take some time.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Why choose Firebase's implementation?

I googled CodeIgniter4 jwt, and found most tutorials use Firebase implementation.
And it is commonly used in my country. So first of all, I chose it.

But I know it doesn't provide the most complete implementation, so I made it replaceable.

@datamweb

Copy link
Copy Markdown
Collaborator

It is also commonly used in my country.

@kenjis
kenjisforce-pushed the feat-jwt branch 4 times, most recently from 443000b to 0a0920eCompareJune 3, 2022 05:22
@kenjiskenjis added the new feature PRs for new features label Aug 8, 2022
Comment threadsrc/Filters/JWTAuth.php Outdated
@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 7c2720f to a85c422CompareOctober 21, 2022 08:31
@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

I don't remember much of the implementation as a lot of time has passed, but I think the implementation itself was done in one way or another.

If there is someone who wants to try JWT, please test. Of course code reviews are also welcome.
I am going to run the code and see if this really works.

@MGatner

Copy link
Copy Markdown
Member

My only JWT CI4 project currently uses Myth and I've had issues installing Shield alongside because they have some conflicting services and factories. I know some community members have been keen on this - maybe check the forums for volunteers?

@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

Good idea! I've posted the forum.

@hainm0912

Copy link
Copy Markdown

it finished? how to use this branch?

@kenjis

Copy link
Copy Markdown
MemberAuthor

This should work. You can get the code from my repository:
https://github.com/kenjis/codeigniter-shield/tree/feat-jwt

@kenjis

Copy link
Copy Markdown
MemberAuthor

how to use this branch?

Update your composer.json:

--- a/composer.json+++ b/composer.json@@ -7,7 +7,8 @@
"require": {
"php": "^7.4 || ^8.0",
"codeigniter4/framework": "^4.0",
- "codeigniter4/shield": "^1.0@beta"+ "codeigniter4/shield": "dev-feat-jwt",+ "firebase/php-jwt": "^6.2"
},
"require-dev": {
"fakerphp/faker": "^1.9",
@@ -36,5 +37,11 @@
"slack": "https://codeigniterchat.slack.com"
},
"minimum-stability": "dev",
- "prefer-stable": true+ "prefer-stable": true,+ "repositories": [+ {+ "type": "vcs",+ "url": "https://github.com/kenjis/codeigniter-shield.git"+ }+ ]
}

Run composer update.

@ghost

Copy link
Copy Markdown

What is the status on JWT authentication?

Any TODOs I could help with?

@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 58f6d62 to 324bcb7CompareApril 13, 2023 23:43
@kenjis

Copy link
Copy Markdown
MemberAuthor

Rebased to resolve conflicts.

@kenjis

Copy link
Copy Markdown
MemberAuthor

What is the status on JWT authentication?

The implementation was finished. I need to write docs.

Any TODOs I could help with?

Testing and review. As you see, no one has approved this PR yet.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner@datamweb Can you review?

@datamweb

Copy link
Copy Markdown
Collaborator

@kenjis will try to do today.

Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threadsrc/Authentication/JWTManager.php
Comment threadsrc/Config/Auth.php Outdated
Comment threadsrc/Config/AuthJWT.php
Comment threadsrc/Language/fa/Auth.php Outdated
@datamweb

Copy link
Copy Markdown
Collaborator

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)

And the next question is there a way to expire the token for a specific user?

Please update the README file, the reference to support JWT is good.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)
And the next question is there a way to expire the token for a specific user?

Tokens are to be validated by defining the conditions that make it invalid.

If you want to invalidate tokens to a specific user, you can do it by specifying the user ID and issued at.

Also, as you say, If you change the key, all tokens signed with that key will be invalidated.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, thanks, everything seems to be working fine now.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@datamweb Thank you for the detailed review!

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner Can you approve? Without your approve, I cannot merge this.

kenjis added a commit to kenjis/codeigniter-shield that referenced this pull request Apr 21, 2023
There is no need to change the status code since a validation error is still an authentication failure.
See codeigniter4#195 (comment)
@kenjis
kenjis merged commit 392bd48 into codeigniter4:developApr 21, 2023
@kenjis
kenjis deleted the feat-jwt branch April 21, 2023 12:26
@kenjis

Copy link
Copy Markdown
MemberAuthor

Thank you all!

@kenjiskenjis mentioned this pull request Apr 22, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 25, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 30, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@kenjis@datamweb@MGatner@hainm0912@lonnieezell@michalsn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat: JWT Authenticator - #195

Merged
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt
Apr 21, 2023
Merged

feat: JWT Authenticator#195
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt

Conversation

@kenjis

@kenjiskenjis commented Jun 1, 2022

Copy link
Copy Markdown
Member

Needs #703
Needs to rebase after merging #194, #199

Add:

  • Config\AuthJWT
  • Authentication\Authenticators\JWT
  • Filters\JWTAuth
  • Authentication\JWTManager = service((jwtmanager)

How to Test/Use:

Sample Test App:

TODO:

  • login recording specification
  • update docs

@kenjis
kenjis marked this pull request as draft June 1, 2022 07:52

@MGatnerMGatner left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking awesome! I had no idea you were working on this, I would have guessed version 1.1 or 1.2.

Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Config/Auth.php Outdated

@lonnieezelllonnieezell left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's great to see a JWT implementation coming! Thanks for this.

However, I do have a couple of concerns with the current implementation.

  1. Choice of implementation. Why choose Firebase's implementation? I think the best reason is probably that it's backed by Google, but according to the the JWT site, it doesn't provide the most complete implementation. That might not be all bad, though. Honestly, I kind of had it in mind that if we ever included JWT we'd roll our own since the implementation of a JWT is pretty straight-forward. Not sure if that's worth considering to remove the reliance on a third-party libs changes, etc.

  2. I think you may have over-architected it. I've commented on a few classes along the way, but in general I think we should strive for as simple of an architecture as the library allows.

This would also require updating all docs and adding new docs.

I don't think we'll be able to get this one in before the initial release.

Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/JWTDecoderInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWT/JWTGeneratorInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWTGenerator.php Outdated
Comment threadsrc/Config/Auth.php Outdated
@kenjis

Copy link
Copy Markdown
MemberAuthor

I don't think we'll be able to get this one in before the initial release.

There are some parts of this feature that require consideration of specifications.
I think it will take some time.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Why choose Firebase's implementation?

I googled CodeIgniter4 jwt, and found most tutorials use Firebase implementation.
And it is commonly used in my country. So first of all, I chose it.

But I know it doesn't provide the most complete implementation, so I made it replaceable.

@datamweb

Copy link
Copy Markdown
Collaborator

It is also commonly used in my country.

@kenjis
kenjisforce-pushed the feat-jwt branch 4 times, most recently from 443000b to 0a0920eCompareJune 3, 2022 05:22
@kenjiskenjis added the new feature PRs for new features label Aug 8, 2022
Comment threadsrc/Filters/JWTAuth.php Outdated
@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 7c2720f to a85c422CompareOctober 21, 2022 08:31
@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

I don't remember much of the implementation as a lot of time has passed, but I think the implementation itself was done in one way or another.

If there is someone who wants to try JWT, please test. Of course code reviews are also welcome.
I am going to run the code and see if this really works.

@MGatner

Copy link
Copy Markdown
Member

My only JWT CI4 project currently uses Myth and I've had issues installing Shield alongside because they have some conflicting services and factories. I know some community members have been keen on this - maybe check the forums for volunteers?

@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

Good idea! I've posted the forum.

@hainm0912

Copy link
Copy Markdown

it finished? how to use this branch?

@kenjis

Copy link
Copy Markdown
MemberAuthor

This should work. You can get the code from my repository:
https://github.com/kenjis/codeigniter-shield/tree/feat-jwt

@kenjis

Copy link
Copy Markdown
MemberAuthor

how to use this branch?

Update your composer.json:

--- a/composer.json+++ b/composer.json@@ -7,7 +7,8 @@
"require": {
"php": "^7.4 || ^8.0",
"codeigniter4/framework": "^4.0",
- "codeigniter4/shield": "^1.0@beta"+ "codeigniter4/shield": "dev-feat-jwt",+ "firebase/php-jwt": "^6.2"
},
"require-dev": {
"fakerphp/faker": "^1.9",
@@ -36,5 +37,11 @@
"slack": "https://codeigniterchat.slack.com"
},
"minimum-stability": "dev",
- "prefer-stable": true+ "prefer-stable": true,+ "repositories": [+ {+ "type": "vcs",+ "url": "https://github.com/kenjis/codeigniter-shield.git"+ }+ ]
}

Run composer update.

@ghost

Copy link
Copy Markdown

What is the status on JWT authentication?

Any TODOs I could help with?

@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 58f6d62 to 324bcb7CompareApril 13, 2023 23:43
@kenjis

Copy link
Copy Markdown
MemberAuthor

Rebased to resolve conflicts.

@kenjis

Copy link
Copy Markdown
MemberAuthor

What is the status on JWT authentication?

The implementation was finished. I need to write docs.

Any TODOs I could help with?

Testing and review. As you see, no one has approved this PR yet.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner@datamweb Can you review?

@datamweb

Copy link
Copy Markdown
Collaborator

@kenjis will try to do today.

Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threadsrc/Authentication/JWTManager.php
Comment threadsrc/Config/Auth.php Outdated
Comment threadsrc/Config/AuthJWT.php
Comment threadsrc/Language/fa/Auth.php Outdated
@datamweb

Copy link
Copy Markdown
Collaborator

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)

And the next question is there a way to expire the token for a specific user?

Please update the README file, the reference to support JWT is good.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)
And the next question is there a way to expire the token for a specific user?

Tokens are to be validated by defining the conditions that make it invalid.

If you want to invalidate tokens to a specific user, you can do it by specifying the user ID and issued at.

Also, as you say, If you change the key, all tokens signed with that key will be invalidated.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, thanks, everything seems to be working fine now.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@datamweb Thank you for the detailed review!

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner Can you approve? Without your approve, I cannot merge this.

kenjis added a commit to kenjis/codeigniter-shield that referenced this pull request Apr 21, 2023
There is no need to change the status code since a validation error is still an authentication failure.
See codeigniter4#195 (comment)
@kenjis
kenjis merged commit 392bd48 into codeigniter4:developApr 21, 2023
@kenjis
kenjis deleted the feat-jwt branch April 21, 2023 12:26
@kenjis

Copy link
Copy Markdown
MemberAuthor

Thank you all!

@kenjiskenjis mentioned this pull request Apr 22, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 25, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 30, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@kenjis@datamweb@MGatner@hainm0912@lonnieezell@michalsn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: JWT Authenticator - #195

Merged
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt
Apr 21, 2023
Merged

feat: JWT Authenticator#195
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt

Conversation

@kenjis

@kenjiskenjis commented Jun 1, 2022

Copy link
Copy Markdown
Member

Needs #703
Needs to rebase after merging #194, #199

Add:

  • Config\AuthJWT
  • Authentication\Authenticators\JWT
  • Filters\JWTAuth
  • Authentication\JWTManager = service((jwtmanager)

How to Test/Use:

Sample Test App:

TODO:

  • login recording specification
  • update docs

@kenjis
kenjis marked this pull request as draft June 1, 2022 07:52

@MGatnerMGatner left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking awesome! I had no idea you were working on this, I would have guessed version 1.1 or 1.2.

Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Config/Auth.php Outdated

@lonnieezelllonnieezell left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's great to see a JWT implementation coming! Thanks for this.

However, I do have a couple of concerns with the current implementation.

  1. Choice of implementation. Why choose Firebase's implementation? I think the best reason is probably that it's backed by Google, but according to the the JWT site, it doesn't provide the most complete implementation. That might not be all bad, though. Honestly, I kind of had it in mind that if we ever included JWT we'd roll our own since the implementation of a JWT is pretty straight-forward. Not sure if that's worth considering to remove the reliance on a third-party libs changes, etc.

  2. I think you may have over-architected it. I've commented on a few classes along the way, but in general I think we should strive for as simple of an architecture as the library allows.

This would also require updating all docs and adding new docs.

I don't think we'll be able to get this one in before the initial release.

Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/JWTDecoderInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWT/JWTGeneratorInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWTGenerator.php Outdated
Comment threadsrc/Config/Auth.php Outdated
@kenjis

Copy link
Copy Markdown
MemberAuthor

I don't think we'll be able to get this one in before the initial release.

There are some parts of this feature that require consideration of specifications.
I think it will take some time.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Why choose Firebase's implementation?

I googled CodeIgniter4 jwt, and found most tutorials use Firebase implementation.
And it is commonly used in my country. So first of all, I chose it.

But I know it doesn't provide the most complete implementation, so I made it replaceable.

@datamweb

Copy link
Copy Markdown
Collaborator

It is also commonly used in my country.

@kenjis
kenjisforce-pushed the feat-jwt branch 4 times, most recently from 443000b to 0a0920eCompareJune 3, 2022 05:22
@kenjiskenjis added the new feature PRs for new features label Aug 8, 2022
Comment threadsrc/Filters/JWTAuth.php Outdated
@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 7c2720f to a85c422CompareOctober 21, 2022 08:31
@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

I don't remember much of the implementation as a lot of time has passed, but I think the implementation itself was done in one way or another.

If there is someone who wants to try JWT, please test. Of course code reviews are also welcome.
I am going to run the code and see if this really works.

@MGatner

Copy link
Copy Markdown
Member

My only JWT CI4 project currently uses Myth and I've had issues installing Shield alongside because they have some conflicting services and factories. I know some community members have been keen on this - maybe check the forums for volunteers?

@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

Good idea! I've posted the forum.

@hainm0912

Copy link
Copy Markdown

it finished? how to use this branch?

@kenjis

Copy link
Copy Markdown
MemberAuthor

This should work. You can get the code from my repository:
https://github.com/kenjis/codeigniter-shield/tree/feat-jwt

@kenjis

Copy link
Copy Markdown
MemberAuthor

how to use this branch?

Update your composer.json:

--- a/composer.json+++ b/composer.json@@ -7,7 +7,8 @@
"require": {
"php": "^7.4 || ^8.0",
"codeigniter4/framework": "^4.0",
- "codeigniter4/shield": "^1.0@beta"+ "codeigniter4/shield": "dev-feat-jwt",+ "firebase/php-jwt": "^6.2"
},
"require-dev": {
"fakerphp/faker": "^1.9",
@@ -36,5 +37,11 @@
"slack": "https://codeigniterchat.slack.com"
},
"minimum-stability": "dev",
- "prefer-stable": true+ "prefer-stable": true,+ "repositories": [+ {+ "type": "vcs",+ "url": "https://github.com/kenjis/codeigniter-shield.git"+ }+ ]
}

Run composer update.

@ghost

Copy link
Copy Markdown

What is the status on JWT authentication?

Any TODOs I could help with?

@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 58f6d62 to 324bcb7CompareApril 13, 2023 23:43
@kenjis

Copy link
Copy Markdown
MemberAuthor

Rebased to resolve conflicts.

@kenjis

Copy link
Copy Markdown
MemberAuthor

What is the status on JWT authentication?

The implementation was finished. I need to write docs.

Any TODOs I could help with?

Testing and review. As you see, no one has approved this PR yet.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner@datamweb Can you review?

@datamweb

Copy link
Copy Markdown
Collaborator

@kenjis will try to do today.

Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threadsrc/Authentication/JWTManager.php
Comment threadsrc/Config/Auth.php Outdated
Comment threadsrc/Config/AuthJWT.php
Comment threadsrc/Language/fa/Auth.php Outdated
@datamweb

Copy link
Copy Markdown
Collaborator

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)

And the next question is there a way to expire the token for a specific user?

Please update the README file, the reference to support JWT is good.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)
And the next question is there a way to expire the token for a specific user?

Tokens are to be validated by defining the conditions that make it invalid.

If you want to invalidate tokens to a specific user, you can do it by specifying the user ID and issued at.

Also, as you say, If you change the key, all tokens signed with that key will be invalidated.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, thanks, everything seems to be working fine now.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@datamweb Thank you for the detailed review!

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner Can you approve? Without your approve, I cannot merge this.

kenjis added a commit to kenjis/codeigniter-shield that referenced this pull request Apr 21, 2023
There is no need to change the status code since a validation error is still an authentication failure.
See codeigniter4#195 (comment)
@kenjis
kenjis merged commit 392bd48 into codeigniter4:developApr 21, 2023
@kenjis
kenjis deleted the feat-jwt branch April 21, 2023 12:26
@kenjis

Copy link
Copy Markdown
MemberAuthor

Thank you all!

@kenjiskenjis mentioned this pull request Apr 22, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 25, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 30, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@kenjis@datamweb@MGatner@hainm0912@lonnieezell@michalsn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: JWT Authenticator - #195

Merged
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt
Apr 21, 2023
Merged

feat: JWT Authenticator#195
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt

Conversation

@kenjis

@kenjiskenjis commented Jun 1, 2022

Copy link
Copy Markdown
Member

Needs #703
Needs to rebase after merging #194, #199

Add:

  • Config\AuthJWT
  • Authentication\Authenticators\JWT
  • Filters\JWTAuth
  • Authentication\JWTManager = service((jwtmanager)

How to Test/Use:

Sample Test App:

TODO:

  • login recording specification
  • update docs

@kenjis
kenjis marked this pull request as draft June 1, 2022 07:52

@MGatnerMGatner left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking awesome! I had no idea you were working on this, I would have guessed version 1.1 or 1.2.

Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Config/Auth.php Outdated

@lonnieezelllonnieezell left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's great to see a JWT implementation coming! Thanks for this.

However, I do have a couple of concerns with the current implementation.

  1. Choice of implementation. Why choose Firebase's implementation? I think the best reason is probably that it's backed by Google, but according to the the JWT site, it doesn't provide the most complete implementation. That might not be all bad, though. Honestly, I kind of had it in mind that if we ever included JWT we'd roll our own since the implementation of a JWT is pretty straight-forward. Not sure if that's worth considering to remove the reliance on a third-party libs changes, etc.

  2. I think you may have over-architected it. I've commented on a few classes along the way, but in general I think we should strive for as simple of an architecture as the library allows.

This would also require updating all docs and adding new docs.

I don't think we'll be able to get this one in before the initial release.

Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/JWTDecoderInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWT/JWTGeneratorInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWTGenerator.php Outdated
Comment threadsrc/Config/Auth.php Outdated
@kenjis

Copy link
Copy Markdown
MemberAuthor

I don't think we'll be able to get this one in before the initial release.

There are some parts of this feature that require consideration of specifications.
I think it will take some time.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Why choose Firebase's implementation?

I googled CodeIgniter4 jwt, and found most tutorials use Firebase implementation.
And it is commonly used in my country. So first of all, I chose it.

But I know it doesn't provide the most complete implementation, so I made it replaceable.

@datamweb

Copy link
Copy Markdown
Collaborator

It is also commonly used in my country.

@kenjis
kenjisforce-pushed the feat-jwt branch 4 times, most recently from 443000b to 0a0920eCompareJune 3, 2022 05:22
@kenjiskenjis added the new feature PRs for new features label Aug 8, 2022
Comment threadsrc/Filters/JWTAuth.php Outdated
@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 7c2720f to a85c422CompareOctober 21, 2022 08:31
@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

I don't remember much of the implementation as a lot of time has passed, but I think the implementation itself was done in one way or another.

If there is someone who wants to try JWT, please test. Of course code reviews are also welcome.
I am going to run the code and see if this really works.

@MGatner

Copy link
Copy Markdown
Member

My only JWT CI4 project currently uses Myth and I've had issues installing Shield alongside because they have some conflicting services and factories. I know some community members have been keen on this - maybe check the forums for volunteers?

@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

Good idea! I've posted the forum.

@hainm0912

Copy link
Copy Markdown

it finished? how to use this branch?

@kenjis

Copy link
Copy Markdown
MemberAuthor

This should work. You can get the code from my repository:
https://github.com/kenjis/codeigniter-shield/tree/feat-jwt

@kenjis

Copy link
Copy Markdown
MemberAuthor

how to use this branch?

Update your composer.json:

--- a/composer.json+++ b/composer.json@@ -7,7 +7,8 @@
"require": {
"php": "^7.4 || ^8.0",
"codeigniter4/framework": "^4.0",
- "codeigniter4/shield": "^1.0@beta"+ "codeigniter4/shield": "dev-feat-jwt",+ "firebase/php-jwt": "^6.2"
},
"require-dev": {
"fakerphp/faker": "^1.9",
@@ -36,5 +37,11 @@
"slack": "https://codeigniterchat.slack.com"
},
"minimum-stability": "dev",
- "prefer-stable": true+ "prefer-stable": true,+ "repositories": [+ {+ "type": "vcs",+ "url": "https://github.com/kenjis/codeigniter-shield.git"+ }+ ]
}

Run composer update.

@ghost

Copy link
Copy Markdown

What is the status on JWT authentication?

Any TODOs I could help with?

@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 58f6d62 to 324bcb7CompareApril 13, 2023 23:43
@kenjis

Copy link
Copy Markdown
MemberAuthor

Rebased to resolve conflicts.

@kenjis

Copy link
Copy Markdown
MemberAuthor

What is the status on JWT authentication?

The implementation was finished. I need to write docs.

Any TODOs I could help with?

Testing and review. As you see, no one has approved this PR yet.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner@datamweb Can you review?

@datamweb

Copy link
Copy Markdown
Collaborator

@kenjis will try to do today.

Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threadsrc/Authentication/JWTManager.php
Comment threadsrc/Config/Auth.php Outdated
Comment threadsrc/Config/AuthJWT.php
Comment threadsrc/Language/fa/Auth.php Outdated
@datamweb

Copy link
Copy Markdown
Collaborator

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)

And the next question is there a way to expire the token for a specific user?

Please update the README file, the reference to support JWT is good.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)
And the next question is there a way to expire the token for a specific user?

Tokens are to be validated by defining the conditions that make it invalid.

If you want to invalidate tokens to a specific user, you can do it by specifying the user ID and issued at.

Also, as you say, If you change the key, all tokens signed with that key will be invalidated.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, thanks, everything seems to be working fine now.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@datamweb Thank you for the detailed review!

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner Can you approve? Without your approve, I cannot merge this.

kenjis added a commit to kenjis/codeigniter-shield that referenced this pull request Apr 21, 2023
There is no need to change the status code since a validation error is still an authentication failure.
See codeigniter4#195 (comment)
@kenjis
kenjis merged commit 392bd48 into codeigniter4:developApr 21, 2023
@kenjis
kenjis deleted the feat-jwt branch April 21, 2023 12:26
@kenjis

Copy link
Copy Markdown
MemberAuthor

Thank you all!

@kenjiskenjis mentioned this pull request Apr 22, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 25, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 30, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@kenjis@datamweb@MGatner@hainm0912@lonnieezell@michalsn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat: JWT Authenticator - #195

Merged
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt
Apr 21, 2023
Merged

feat: JWT Authenticator#195
kenjis merged 101 commits into
codeigniter4:developfrom
kenjis:feat-jwt

Conversation

@kenjis

@kenjiskenjis commented Jun 1, 2022

Copy link
Copy Markdown
Member

Needs #703
Needs to rebase after merging #194, #199

Add:

  • Config\AuthJWT
  • Authentication\Authenticators\JWT
  • Filters\JWTAuth
  • Authentication\JWTManager = service((jwtmanager)

How to Test/Use:

Sample Test App:

TODO:

  • login recording specification
  • update docs

@kenjis
kenjis marked this pull request as draft June 1, 2022 07:52

@MGatnerMGatner left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is looking awesome! I had no idea you were working on this, I would have guessed version 1.1 or 1.2.

Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Config/Auth.php Outdated

@lonnieezelllonnieezell left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's great to see a JWT implementation coming! Thanks for this.

However, I do have a couple of concerns with the current implementation.

  1. Choice of implementation. Why choose Firebase's implementation? I think the best reason is probably that it's backed by Google, but according to the the JWT site, it doesn't provide the most complete implementation. That might not be all bad, though. Honestly, I kind of had it in mind that if we ever included JWT we'd roll our own since the implementation of a JWT is pretty straight-forward. Not sure if that's worth considering to remove the reliance on a third-party libs changes, etc.

  2. I think you may have over-architected it. I've commented on a few classes along the way, but in general I think we should strive for as simple of an architecture as the library allows.

This would also require updating all docs and adding new docs.

I don't think we'll be able to get this one in before the initial release.

Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php
Comment threadsrc/Authentication/Authenticators/JWT.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/Firebase.php Outdated
Comment threadsrc/Authentication/Authenticators/JWT/JWTDecoderInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWT/JWTGeneratorInterface.php Outdated
Comment threadsrc/Authentication/TokenGenerator/JWTGenerator.php Outdated
Comment threadsrc/Config/Auth.php Outdated
@kenjis

Copy link
Copy Markdown
MemberAuthor

I don't think we'll be able to get this one in before the initial release.

There are some parts of this feature that require consideration of specifications.
I think it will take some time.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Why choose Firebase's implementation?

I googled CodeIgniter4 jwt, and found most tutorials use Firebase implementation.
And it is commonly used in my country. So first of all, I chose it.

But I know it doesn't provide the most complete implementation, so I made it replaceable.

@datamweb

Copy link
Copy Markdown
Collaborator

It is also commonly used in my country.

@kenjis
kenjisforce-pushed the feat-jwt branch 4 times, most recently from 443000b to 0a0920eCompareJune 3, 2022 05:22
@kenjiskenjis added the new feature PRs for new features label Aug 8, 2022
Comment threadsrc/Filters/JWTAuth.php Outdated
@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 7c2720f to a85c422CompareOctober 21, 2022 08:31
@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

I don't remember much of the implementation as a lot of time has passed, but I think the implementation itself was done in one way or another.

If there is someone who wants to try JWT, please test. Of course code reviews are also welcome.
I am going to run the code and see if this really works.

@MGatner

Copy link
Copy Markdown
Member

My only JWT CI4 project currently uses Myth and I've had issues installing Shield alongside because they have some conflicting services and factories. I know some community members have been keen on this - maybe check the forums for volunteers?

@kenjis

kenjis commented Oct 21, 2022

Copy link
Copy Markdown
MemberAuthor

Good idea! I've posted the forum.

@hainm0912

Copy link
Copy Markdown

it finished? how to use this branch?

@kenjis

Copy link
Copy Markdown
MemberAuthor

This should work. You can get the code from my repository:
https://github.com/kenjis/codeigniter-shield/tree/feat-jwt

@kenjis

Copy link
Copy Markdown
MemberAuthor

how to use this branch?

Update your composer.json:

--- a/composer.json+++ b/composer.json@@ -7,7 +7,8 @@
"require": {
"php": "^7.4 || ^8.0",
"codeigniter4/framework": "^4.0",
- "codeigniter4/shield": "^1.0@beta"+ "codeigniter4/shield": "dev-feat-jwt",+ "firebase/php-jwt": "^6.2"
},
"require-dev": {
"fakerphp/faker": "^1.9",
@@ -36,5 +37,11 @@
"slack": "https://codeigniterchat.slack.com"
},
"minimum-stability": "dev",
- "prefer-stable": true+ "prefer-stable": true,+ "repositories": [+ {+ "type": "vcs",+ "url": "https://github.com/kenjis/codeigniter-shield.git"+ }+ ]
}

Run composer update.

@ghost

Copy link
Copy Markdown

What is the status on JWT authentication?

Any TODOs I could help with?

@kenjis
kenjisforce-pushed the feat-jwt branch 2 times, most recently from 58f6d62 to 324bcb7CompareApril 13, 2023 23:43
@kenjis

Copy link
Copy Markdown
MemberAuthor

Rebased to resolve conflicts.

@kenjis

Copy link
Copy Markdown
MemberAuthor

What is the status on JWT authentication?

The implementation was finished. I need to write docs.

Any TODOs I could help with?

Testing and review. As you see, no one has approved this PR yet.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner@datamweb Can you review?

@datamweb

Copy link
Copy Markdown
Collaborator

@kenjis will try to do today.

Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threaddocs/addons/jwt.md Outdated
Comment threadsrc/Authentication/JWTManager.php
Comment threadsrc/Config/Auth.php Outdated
Comment threadsrc/Config/AuthJWT.php
Comment threadsrc/Language/fa/Auth.php Outdated
@datamweb

Copy link
Copy Markdown
Collaborator

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)

And the next question is there a way to expire the token for a specific user?

Please update the README file, the reference to support JWT is good.

@kenjis

Copy link
Copy Markdown
MemberAuthor

Question, how can the site administrator make the tokens expire in general? (I think he should change the secret code. If so, I'd prefer you explain it in the documentation.)
And the next question is there a way to expire the token for a specific user?

Tokens are to be validated by defining the conditions that make it invalid.

If you want to invalidate tokens to a specific user, you can do it by specifying the user ID and issued at.

Also, as you say, If you change the key, all tokens signed with that key will be invalidated.

@datamwebdatamweb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kenjis, thanks, everything seems to be working fine now.

@kenjis

Copy link
Copy Markdown
MemberAuthor

@datamweb Thank you for the detailed review!

@kenjis

Copy link
Copy Markdown
MemberAuthor

@MGatner Can you approve? Without your approve, I cannot merge this.

kenjis added a commit to kenjis/codeigniter-shield that referenced this pull request Apr 21, 2023
There is no need to change the status code since a validation error is still an authentication failure.
See codeigniter4#195 (comment)
@kenjis
kenjis merged commit 392bd48 into codeigniter4:developApr 21, 2023
@kenjis
kenjis deleted the feat-jwt branch April 21, 2023 12:26
@kenjis

Copy link
Copy Markdown
MemberAuthor

Thank you all!

@kenjiskenjis mentioned this pull request Apr 22, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 25, 2023
kenjis added a commit to kenjis/CodeIgniter4 that referenced this pull request Apr 30, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new featurePRs for new features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@kenjis@datamweb@MGatner@hainm0912@lonnieezell@michalsn