mamluk/kipchak/libraries/identity
0 forks
Consumer and tenant identity for the Kipchak API Development Kit (ADK): who a request is from, read from API keys, verified tokens, request attributes or headers, defined once and shared by metering and quotas.
id: 242
939 Lines
  • PHP 89.6%
  • Markdown 5.5%
  • JSON 4%
  • XML 0.9%
README.md

Kipchak Identity

Who a request is from: the consumer it is billed and limited as, and the tenant it belongs to, read from API keys (kipchak/middleware-auth-key), verified tokens (auth-jwks, auth-jwt), signed requests (auth-hmac), request attributes, headers or your own function.

It is defined once, in config/kipchak.identity.php, and shared by Usage Metering and Subashi Pro quotas, so a client is the same consumer on the bill and in the limits. Those packages install it; there is nothing to initialise.

Documentation: https://kipchak.dev/docs/identity. Sample config: sample.config.php.

Composer Package

kipchak/identity

Sources

SourceReads
tokenA claim of the token auth-jwks or auth-jwt verified (the kipchak.auth.token request attribute).
api_keyThe client name for the request's key in kipchak.auth.key.
attributeA request attribute, optionally a claim path into it.
headerA request header, optionally hashed.
callablefn (ServerRequestInterface $request): ?string.

Any source can take a map that translates what it found into a name.

Using it in a package

use Kipchak\Identity\Identity;

// The package's own 'consumer' / 'tenant' keys where set, kipchak.identity otherwise.
$identity = Identity::forPackage($packageConfig, 'kipchak.my-package');

$consumer = $identity->consumerOf($request);
$tenant = $identity->tenantOf($request);

Invalid sources raise Kipchak\Identity\InvalidConfiguration at boot, naming the config file and key.

Tests

composer install
./vendor/bin/phpunit

Licence

MIT

Please wait...
Connection lost or session expired, reload to recover
Page is in error, reload to recover