Simple Keycloak Guard for Laravel
This package helps you authenticate users on a Laravel API based on JWT tokens generated from Keycloak Server.
Requirements
The flow
-
The frontend user authenticates on Keycloak Server
-
The frontend user obtains a JWT token.
-
In another moment, the frontend user makes a request to some protected endpoint on a Laravel API, with that token.
-
The Laravel API (through
Keycloak Guard
) handle it.- Verify token signature.
- Verify token structure.
- Verify token expiration time.
- Verify if my API allows
resource access
from token.
-
If everything is ok, then find the user on database and authenticate it on my API.
-
Optionally, the user can be created / updated in the API users database.
-
Return response
Install
Laravel / Lumen
Require the package
composer require robsontenorio/laravel-keycloak-guard
Lumen only
Register the provider in your boostrap app file bootstrap/app.php
Add the following line in the "Register Service Providers" section at the bottom of the file.
$app->register(\KeycloakGuard\KeycloakGuardServiceProvider::class);
For facades, uncomment $app->withFacades();
in your boostrap app file bootstrap/app.php
Configuration
Keycloak Guard
.env
make sure all strings are trimmed.
# Publish config file
php artisan vendor:publish --provider="KeycloakGuard\KeycloakGuardServiceProvider"
Required.
The Keycloak Server realm public key (string).
How to get realm public key? Click on "Realm Settings" > "Keys" > "Algorithm RS256" Line > "Public Key" Button
Required. Default is true
.
If you do not have an users
table you must disable this.
It fetchs user from database and fill values into authenticated user object. If enabled, it will work together with user_provider_credential
and token_principal_attribute
.
Default is null
.
If you have an users
table and want it to be updated (creating or updating users) based on the token, you can inform a custom method on a custom UserProvider, that will be called instead retrieveByCredentials
and will receive the complete decoded token as parameter, not just the credentials (as default).
This will allow you to customize the way you want to interact with your database, before matching and delivering the authenticated user object, having all the information contained in the (valid) access token available. To read more about custom UserProviders, please check Laravel's documentation about.
If using this feature, obviously, values defined for user_provider_credential
and token_principal_attribute
will be ignored.
Required.
Default is username
.
The field from "users" table that contains the user unique identifier (eg. username, email, nickname). This will be confronted against token_principal_attribute
attribute, while authenticating.
Required.
Default is preferred_username
.
The property from JWT token that contains the user identifier.
This will be confronted against user_provider_credential
attribute, while authenticating.
Default is false
.
Appends to the authenticated user the full decoded JWT token ($user->token
). Useful if you need to know roles, groups and other user info holded by JWT token. Even choosing false
, you can also get it using Auth::token()
, see API section.
Required.
Usually you API should handle one resource_access. But, if you handle multiples, just use a comma separated list of allowed resources accepted by API. This attribute will be confronted against resource_access
attribute from JWT token, while authenticating.
Default is false
.
Disables entirely resources validation. It will ignore allowed_resources configuration.
Default is 0
.
You can add a leeway to account for when there is a clock skew times between the signing and verifying servers. If you are facing issues like "Cannot handle token prior to " try to set it 60
(seconds).
Default is null
.
By default this package always will look at first for a Bearer
token. Additionally, if this option is enabled, then it will try to get a token from this custom request param.
// keycloak.php
'input_key' => 'api_token'
// If there is no Bearer token on request it will use `api_token` request param
GET $this->get("/foo/secret?api_token=xxxxx")
POST $this->post("/foo/secret", ["api_token" => "xxxxx"])
Laravel Auth
Changes on config/auth.php
...
'defaults' => [
'guard' => 'api', # <-- For sure, i`m building an API
'passwords' => 'users',
],
....
'guards' => [
# <!-----
# Make sure your "api" guard looks like this.
# Newer Laravel versions just removed this config block.
# ---->
'api' => [
'driver' => 'keycloak',
'provider' => 'users',
],
],
Laravel Routes
Just protect some endpoints on routes/api.php
and you are done!
// public endpoints
Route::get('/hello', function () {
return ':)';
});
// protected endpoints
Route::group(['middleware' => 'auth:api'], function () {
Route::get('/protected-endpoint', 'SecretController@index');
// more endpoints ...
});
Lumen Routes
Just protect some endpoints on routes/web.php
and you are done!
// public endpoints
$router->get('/hello', function () {
return ':)';
});
// protected endpoints
$router->group(['middleware' => 'auth'], function () {
$router->get('/protected-endpoint', 'SecretController@index');
// more endpoints ...
});
API
Simple Keycloak Guard implements Illuminate\Contracts\Auth\Guard
. So, all Laravel default methods will be available.
Default Laravel methods
check()
guest()
user()
id()
validate()
setUser()
Keycloak Guard methods
token()
Returns full decoded JWT token from authenticated user.
$token = Auth::token() // or Auth::user()->token()
hasRole('some-resource', 'some-role')
Check if authenticated user has a role on resource_access
// Example decoded payload
'resource_access' => [
'myapp-backend' => [
'roles' => [
'myapp-backend-role1',
'myapp-backend-role2'
]
],
'myapp-frontend' => [
'roles' => [
'myapp-frontend-role1',
'myapp-frontend-role2'
]
]
]
Auth::hasRole('myapp-backend', 'myapp-backend-role1') // true
Auth::hasRole('myapp-frontend', 'myapp-frontend-role1') // true
Auth::hasRole('myapp-backend', 'myapp-frontend-role1') // false
hasAnyRole('some-resource', ['some-role1', 'some-role2'])
Check if the authenticated user has any of the roles in resource_access
Auth::hasAnyRole('myapp-backend', ['myapp-backend-role1', 'myapp-backend-role3']) // true
Auth::hasAnyRole('myapp-frontend', ['myapp-frontend-role1', 'myapp-frontend-role3']) // true
Auth::hasAnyRole('myapp-backend', ['myapp-frontend-role1', 'myapp-frontend-role2']) // false
Contribute
You can run this project on VSCODE with Remote Container. Make sure you will use internal VSCODE terminal (inside running container).
composer install
composer test
composer test:coverage
Contact
Twitter @robsontenorio