iachilles/pjwt
Composer 安装命令:
composer require iachilles/pjwt
包简介
PHP implementation of JSON Web Token (JWT). It provides a simple way to create, sign and verify JWT.
关键字:
README 文档
README
pJWT
PHP implementation of JSON Web Token (JWT). It provides a simple way to create, sign and verify JWT.
The following features are supported:
- Built-in validation for the JWT claims (iat, nbf, exp, jti).
- Symmetric and asymmetric algorithms for protecting integrity:
| Symmetric | Asymmetric |
|---|---|
| HS256 | RS256 |
| HS384 | RS384 |
| HS512 | RS512 |
Requirements
PHP 5.4.0 or above.
Installation
Use composer to install pJWT:
composer require iachilles/pjwt
Code examples
- Creating JWT
- by using symmetric algorithm HS256:
$claims = ['iat' => time(), 'nbf' => time(), 'exp' => strtotime('+1 day'), 'iss' => 'domain.com', 'uid' => 1]; $headers = ['alg' => 'HS256', 'typ' => 'JWT']; $jws = new Jws($headers, $claims); $jws->privateKey = 'YoUr_SeCrEt'; $jws->sign(); //Returns URL-safe string representation of the digitally signed JWT. This encoded JWT can be sent to a user.
- by using asymmetric algorithm RS256:
$claims = ['iat' => time(), 'nbf' => time(), 'exp' => strtotime('+1 day'), 'iss' => 'domain.com', 'uid' => 1]; $headers = ['alg' => 'RS256', 'typ' => 'JWT']; $jws = new Jws($headers, $claims); $jws->privateKey = 'file:///path/to/private/key.pem'; //Path to the PEM encoded private key. $jws->sign(); //Returns URL-safe string representation of the digitally signed JWT. This encoded JWT can be sent to a user.
If the private key is encrypted with a password, you can use the following format:
$jws->privateKey = ['file:///path/to/private/key.pem', 'pAsSwOrd'];
- with protection from replay attacks. In order to protect from replay attacks, you can set 'jti' claim to TRUE during creation JWT.
$claims = ['jti' => true, 'iat' => time(), 'nbf' => time(), 'exp' => strtotime('+1 day')]; $headers = ['alg' => 'RS256', 'typ' => 'JWT']; $jws = new Jws($headers, $claims);
-
Decoding and verifying JWT
$encodedJwt = 'abcdef.ghijklm.nopqrstuvw'; $jws = Jws::parse($encodedJwt); $jws->getPayload()->issuedAt; //Access to the registered JWT claims $jws->getPayload()->getCustomClaim('user_id'); //Access to the custom claims. $jws->getHeader()->getAlgorithm(); //Access to the JOSE header parameters.
Verifying signature
```php
$encodedJwt = 'abcdef.ghijklm.nopqrstuvw';
$jws = Jws::parse($encodedJwt);
//For symmetric algorithm:
$jws->privateKey = 'YoUr_SeCrEt';
//For asymmetric algorithm:
$jws->certificate = 'file:///path/to/certificate.pem'; //Path to the PEM encoded X.509 certificate.
$jws->verify(); //TRUE if the signature is valid.
If the signature is valid, you have to validate the JWT claims.
$jws->getPayload()->verify(); //Returns TRUE if the JWT is valid, otherwise it returns a string that contains an error message.
To validate "jti" value you need to create two anonymous functions, and pass them as arguments to the verify method.
$setJti = function($jti) { //Writes "jti" value into storage. (E.g. Redis Db) }; //This function must return TRUE if the given value exists in storage, false otherwise. $getJti = function($jti) { //... }; $jws->getPayload()->verify($setJti, $getJti);
iachilles/pjwt 适用场景与选型建议
iachilles/pjwt 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 44 次下载、GitHub Stars 达 4, 最近一次更新时间为 2014 年 11 月 23 日, 在 PHP 生态内属于活跃度较高的组件。
它主要适用于以下技术方向: 「token」 「jwt」 「JSON Web Token」 「JWS」 等业务场景。在实际项目中,围绕这些方向常见需要落地的问题包括:接口对接、性能调优、并发安全、与既有框架(Laravel / ThinkPHP / Yii / Webman 等)的兼容适配,以及生产环境的日志埋点与稳定性保障。
我们在过去多个企业项目中使用过 iachilles/pjwt 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。
基于 iachilles/pjwt 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。
线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。
承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。
与 iachilles/pjwt 相关的其它包
同方向 / 同关键字的高下载量 PHP Composer 包推荐,方便对比选型:
Kinikit - PHP Application development framework MVC component
A simple library to decode and parse Apple Sign In client tokens.
ext-json wrapper with sane defaults
A package for validating Google Cloud's JWT provided by webhooks
JSON Web Token Authentication for Laravel and Lumen
A package to cast json fields, each sub-keys is castable
统计信息
- 总下载量: 44
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 4
- 点击次数: 21
- 依赖项目数: 0
- 推荐数: 0
其他信息
- 授权协议: AGPL
- 更新时间: 2014-11-23