acato/ms-entra-guard
Composer 安装命令:
composer require acato/ms-entra-guard
包简介
Laravel authentication guard for Microsoft Entra ID (Azure AD) JWT bearer tokens
README 文档
README
A Laravel authentication guard for validating Microsoft Entra ID (Azure AD) JWT bearer tokens.
Requirements
- PHP 8.2+
- Laravel 11.0+
Installation
composer require acato/ms-entra-guard
The service provider is auto-discovered. Publish the config file:
php artisan vendor:publish --tag=entra-guard-config
Configuration
1. Add a guard to config/auth.php
'guards' => [
// ...
'api' => [
'driver' => 'entra',
'provider' => null,
],
],
2. Configure trusted providers in config/entra-guard.php
'providers' => [
[
'iss' => 'https://login.microsoftonline.com/{tenant-id}/v2.0',
'alg' => \Lcobucci\JWT\Signer\Rsa\Sha256::class,
'claims' => [
'aud' => 'your-client-id',
],
],
],
3. Implement the interface on your User model
use Acato\EntraGuard\Contracts\ResolvesFromEntraToken;
use Acato\EntraGuard\Concerns\ResolvesEntraUser;
use Illuminate\Foundation\Auth\User as Authenticatable;
class User extends Authenticatable implements ResolvesFromEntraToken
{
use ResolvesEntraUser;
}
The ResolvesEntraUser trait provides a default updateOrCreate implementation. Customize the field mapping with static properties:
class User extends Authenticatable implements ResolvesFromEntraToken
{
use ResolvesEntraUser;
// Map DB columns to JWT claims for the unique key
protected static array $entraUniqueBy = [
'uuid' => 'oid',
];
// Map DB columns to JWT claims for update values
// Use '|' for fallback (tries left-to-right), null inserts now()
protected static array $entraUpdateAttributes = [
'name' => 'name',
'email' => 'email|upn',
'last_login_at' => null,
];
}
Alternative: custom user resolver
Instead of implementing the interface, you can provide a closure in the config:
'user_resolver' => function (array $payload) {
return \App\Models\User::where('azure_id', $payload['oid'])->first();
},
Usage
Protect routes with the guard:
Route::middleware('auth:api')->group(function () {
Route::get('/me', fn () => auth()->user());
});
Testing
Use actingAs in your tests:
use Acato\EntraGuard\EntraGuard;
EntraGuard::actingAs($user, 'api');
Config Options
| Key | Type | Default | Description |
|---|---|---|---|
model | class-string | App\Models\User | Eloquent model implementing ResolvesFromEntraToken |
user_resolver | ?Closure | null | Custom resolver (takes precedence over model) |
token_cache_ttl | int | 10 | Minutes to cache decoded tokens |
key_cache_ttl | int | 4 | Hours to cache public signing keys |
timezone | string | app timezone | Timezone for JWT time validation |
providers | array | [] | Trusted issuer configurations |
License
Apache-2.0. See LICENSE for details.
acato/ms-entra-guard 适用场景与选型建议
acato/ms-entra-guard 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 0 次下载、GitHub Stars 达 0, 最近一次更新时间为 2026 年 02 月 24 日, 在 PHP 生态内属于活跃度较高的组件。
它主要适用于以下技术方向: 「Authentication」 「laravel」 「microsoft」 「jwt」 「guard」 「azure-ad」 等业务场景。在实际项目中,围绕这些方向常见需要落地的问题包括:接口对接、性能调优、并发安全、与既有框架(Laravel / ThinkPHP / Yii / Webman 等)的兼容适配,以及生产环境的日志埋点与稳定性保障。
我们在过去多个企业项目中使用过 acato/ms-entra-guard 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。
基于 acato/ms-entra-guard 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。
线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。
承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。
与 acato/ms-entra-guard 相关的其它包
同方向 / 同关键字的高下载量 PHP Composer 包推荐,方便对比选型:
Automatically logs-in users if they are already authenticated by a remote source. (e.g. environment variable REMOTE_USER)
GraphQL authentication for your headless Craft CMS applications.
A simple PHP package for sending messages to Microsoft Teams
Laravel middleware to restrict a site or specific routes using HTTP basic authentication
Email Toolkit Plugin for CakePHP
Laravel 5 Queue Driver for Microsoft Azure Storage Queue
统计信息
- 总下载量: 0
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 0
- 点击次数: 37
- 依赖项目数: 0
- 推荐数: 0
其他信息
- 授权协议: Apache-2.0
- 更新时间: 2026-02-24