A comprehensive Laravel authentication package with support for registration, login, password reset, OAuth integration, and configurable email/phone verification.
-
Complete Authentication System:
- User registration with customizable fields
- Login with email, phone, or username
- Password reset functionality
- OAuth integration (Google, Apple, etc.)
-
Email/Phone Verification:
- Configurable verification before registration
- Event-driven integration with any email/SMS provider
- Built-in SmartPings integration for managed verification
- Rate limiting and security features
- 5-minute code expiry (configurable)
-
Developer-Friendly:
- OpenAPI documentation with PHP attributes
- Customizable response formatting
- Middleware hooks for custom logic
- Event system for extensibility
-
Security Features:
- Backend verification validation
- Rate limiting protection
- Secure code generation and storage
composer require whilesmart/laravel-user-authentication
php artisan migrateThat's it! The package will auto-register routes and work out of the box.
For hassle-free verification with SmartPings handling the entire flow:
# .env
USER_AUTH_REQUIRE_EMAIL_VERIFICATION=true
USER_AUTH_REQUIRE_PHONE_VERIFICATION=false
USER_AUTH_VERIFICATION_PROVIDER=smartpings
USER_AUTH_SELF_MANAGED=false
USER_AUTH_ROUTE_PREFIX=api
SMARTPINGS_CLIENT_ID=your-client-id
SMARTPINGS_SECRET_ID=your-secret-idAll configuration is now environment-driven for better deployment flexibility.
Set up email or phone verification with event-driven integration:
# .env
USER_AUTH_REQUIRE_EMAIL_VERIFICATION=true
USER_AUTH_REQUIRE_PHONE_VERIFICATION=false
USER_AUTH_VERIFICATION_PROVIDER=default
USER_AUTH_SELF_MANAGED=true
USER_AUTH_CODE_LENGTH=6
USER_AUTH_CODE_EXPIRY_MINUTES=5
USER_AUTH_RATE_LIMIT_ATTEMPTS=3
USER_AUTH_RATE_LIMIT_MINUTES=5
USER_AUTH_ROUTE_PREFIX=apiCreate event listeners to send codes via your preferred provider:
class SendVerificationCodeEmailListener {
public function handle(VerificationCodeGeneratedEvent $event) {
Mail::raw("Your code: {$event->code}", function($msg) use ($event) {
$msg->to($event->contact)->subject('Verification Code');
});
}
}📖 Complete Verification Setup Guide
All package configuration is now environment-driven. Add these variables to your .env file:
# Route prefix for all authentication endpoints (default: api)
USER_AUTH_ROUTE_PREFIX=api# Email verification (default: false)
USER_AUTH_REQUIRE_EMAIL_VERIFICATION=false
# Phone verification (default: false)
USER_AUTH_REQUIRE_PHONE_VERIFICATION=false
# Verification provider: 'default' or 'smartpings' (default: default)
USER_AUTH_VERIFICATION_PROVIDER=default
# Self-managed verification (default: true)
# Set to false when using SmartPings to let them handle the flow
USER_AUTH_SELF_MANAGED=true
# Verification code length (default: 6)
USER_AUTH_CODE_LENGTH=6
# Code expiry time in minutes (default: 5)
USER_AUTH_CODE_EXPIRY_MINUTES=5
# Rate limiting attempts before blocking (default: 3)
USER_AUTH_RATE_LIMIT_ATTEMPTS=3
# Rate limiting window in minutes (default: 5)
USER_AUTH_RATE_LIMIT_MINUTES=5# Required when USER_AUTH_VERIFICATION_PROVIDER=smartpings
SMARTPINGS_CLIENT_ID=your-client-id
SMARTPINGS_SECRET_ID=your-secret-idPOST /api/register- Register a new userPOST /api/login- User loginPOST /api/logout- User logoutPOST /api/send-verification-code- Send verification codePOST /api/verify-code- Verify submitted codePOST /api/password/reset-code- Request password resetPOST /api/password/reset- Reset passwordGET /api/oauth/{provider}/login- OAuth loginGET /api/oauth/{provider}/callback- OAuth callbackPOST /api/oauth/firebase/{provider}/callback- Firebase OAuth callback. See the Laravel Firebase Package for Firebase configurations.
The package dispatches events for extensibility:
UserRegisteredEvent- After successful registrationUserLoggedInEvent- After successful loginUserLoggedOutEvent- After logoutVerificationCodeGeneratedEvent- When verification codes are generatedPasswordResetCodeGeneratedEvent- When password reset codes are generatedPasswordResetCompleteEvent- After password reset
To include the authentication endpoints in your OpenAPI specification, publish the documentation class:
php artisan vendor:publish --provider="Whilesmart\UserAuthentication\UserAuthenticationServiceProvider" --tag="laravel-user-authentication-docs"This will create app/Http/Documentation/UserAuthOpenApiDocs.php containing all OpenAPI attributes for the authentication endpoints. Your OpenAPI generator will automatically discover and include these endpoints.
# Publish only documentation
php artisan vendor:publish --tag="laravel-user-authentication-docs"
# Publish only configuration
php artisan vendor:publish --tag="laravel-user-authentication-config"
# Publish everything
php artisan vendor:publish --provider="Whilesmart\UserAuthentication\UserAuthenticationServiceProvider"Apple Oauth is provided by SocialLite Providers. Please see the steps outlined here to configure Apple Oauth
- 📖 Installation Guide - Complete installation instructions
- 📖 Email/Phone Verification - Set up verification with any provider
- 📖 Customization Guide - Response formatting, middleware hooks
composer test- Run unit testscomposer phpmd- Run Mess Detector checkscomposer phpstan- Run Static Analysis checkscomposer phpcs- Run PHP code style checkscomposer pint- Run Laravel code style checkscomposer openapi- Run open api documentation generation
This project is licensed under the MIT License - see the LICENSE file for details.