33Authentication is the process by which an identity is presented to the application. It ensures that the entity
44making the request has the proper credentials to access the API.
55
6- DotKernel's API identities are delivered to the application from the client through the ` Authorization ` request
7- header. If it is present, the application tries to find and assign the identity to the application. If it is not presented,
8- DotKernel's API assigns a default ` guest ` identity, represented by an instance of the class
6+ DotKernel API identities are delivered to the application from the client through the ` Authorization ` request
7+ If it is present, the application tries to find and assign the identity to the application. If it is not presented,
8+ DotKernel API assigns a default ` guest ` identity, represented by an instance of the class
99` Mezzio\Authentication\UserInterface ` .
1010
1111## Configuration
1212
13- DotKernel's API authentication is made around ` mezzio/mezzio-authentication-oauth2 ` component and is already configured.
14- with what is necessary in order to work. But if you want to dig more, the configuration is hold on.
15- ` config/autoload/local.php ` under the authentication key.
13+ Authentication in DotKernel API is built around ` mezzio/mezzio-authentication-oauth2 ` component and is already configured
14+ with what is necessary in order to work. But if you want to dig more, the configuration is stored in
15+ ` config/autoload/local.php ` under the ` authentication ` key.
1616
1717> You can check the [ mezzio/mezzio-authentication-oauth2] ( https://docs.mezzio.dev/mezzio-authentication-oauth2/v1/intro/#configuration )
18- > configuration part for more digging .
18+ > configuration part for more info .
1919
2020## How it works
2121
22- DotKernel's API authentication system can be used for SPAs (single-page applications), mobile applications, and
22+ DotKernels API authentication system can be used for SPAs (single-page applications), mobile applications, and
2323simple, token-based APIs. It allows each user of your application to generate API tokens for their accounts.
2424
2525The authentication happens through the middleware in the ` Api\App\Middleware\AuthenticationMiddleware ` .
2626
2727## Database
2828
2929When DotKernel API is installed for the first time, and you run the migrations and seeders, all the tables
30- needed for authentication are automatically created and inserted with the data needed for authentication.
30+ needed for authentication are automatically created and populated with the data needed for authentication.
3131
32- In DotKernel's API, authentication users can be from the ` admin ` table and from the ` users ` table. We choose to keep the admin
32+ In DotKernel API, authenticated users come from either the ` admin ` or the ` users ` table. We choose to keep the admin
3333table separated from the users to prevent users of the application from accessing sensitive data, which only the administrators
3434of the application should access.
3535
3636Knowing this, upon migrations, the ` oauth_clients ` table is pre-populated with the default ` admin ` and ` frontend ` clients with
37- the same password as their names. (you can change those passwords. ).
37+ the same password as their names (you can change those passwords).
3838
39- As you guested each client serves to authenticate ` admin ` or ` users ` .
39+ As you guessed each client serves to authenticate ` admin ` or ` users ` .
4040
4141Another table that is pre-populated is the ` oauth_scopes ` table, with the ` api ` scope.
4242
4343### Issuing API Tokens
4444
45- In DotKernel's API, generating tokens is done using the ` password ` ` grand_type ` scenario, which in this case allows authentication
45+ Token generation in DotKernel API is done using the ` password ` ` grand_type ` scenario, which in this case allows authentication
4646to an API using the user's credentials (generally a username and password).
4747
4848The client sends a POST request to the ` /security/generate-token ` with the following parameters:
4949
5050- ` grant_type ` = password.
51- - ` client_id ` with the client name ( from ` oauth_clients ` table).
52- - ` client_secret ` with the client secret (password from ` oauth_clients ` table for the client).
53- - ` scope ` with the scope from ` oauth_scopes ` table.
54- - ` username ` with the user’s username.
55- - ` password ` with the user’s password.
51+ - ` client_id ` = column ` name ` from the ` oauth_clients ` table
52+ - ` client_secret ` = column ` secret ` from the ` oauth_clients ` table
53+ - ` scope ` = column ` scope ` from the ` oauth_scopes ` table
54+ - ` username ` = column ` identity ` from table ` admin ` / ` user `
55+ - ` password ` = column ` password ` from table ` admin ` / ` user `
5656
5757``` shell
5858POST /security/generate-token HTTP/1.1
5959Accept: application/json
6060Content-Type: application/json
6161{
62- " grant_type" : " password" ,
63- " client_id" : " frontend" ,
64- " client_secret" : " frontend" ,
65- " scope" : " api" ,
66- " username" : " test@dotkernel.com" ,
67- " password" : " dotkernel"
62+ " grant_type" : " password" ,
63+ " client_id" : " frontend" ,
64+ " client_secret" : " frontend" ,
65+ " scope" : " api" ,
66+ " username" : " test@dotkernel.com" ,
67+ " password" : " dotkernel"
6868}
6969```
7070
7171The server responds with a JSON as follows:
7272
73- ``` php
73+ ``` json
7474{
75- "token_type": "Bearer",
76- "expires_in": 86400,
77- "access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9...",
78- "refresh_token": "def5020087199939a49d0f2f818..."
75+ "token_type" : " Bearer" ,
76+ "expires_in" : 86400 ,
77+ "access_token" : " eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9..." ,
78+ "refresh_token" : " def5020087199939a49d0f2f818..."
7979}
8080```
8181
@@ -90,7 +90,7 @@ Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9...
9090
9191### Refreshing tokens
9292
93- DotKernel's API provides the ability to refresh the access token, generating a new one.
93+ DotKernel API provides the ability to refresh the access token, by generating a new one using the expired access token's ` refresh_token ` .
9494
9595The clients need to send a ` POST ` request to the ` /security/refresh-token ` with the following request
9696
@@ -99,21 +99,21 @@ POST /security/refresh-token HTTP/1.1
9999Accept: application/json
100100Content-Type: application/json
101101{
102- " grant_type" : " refresh_token" ,
103- " client_id" : " frontend" ,
104- " client_secret" : " frontend" ,
105- " scope" : " api" ,
106- " refresh_token" : " def5020087199939a49d0f2f818..."
102+ " grant_type" : " refresh_token" ,
103+ " client_id" : " frontend" ,
104+ " client_secret" : " frontend" ,
105+ " scope" : " api" ,
106+ " refresh_token" : " def5020087199939a49d0f2f818..."
107107}
108108```
109109
110110The server responds with a JSON as follows:
111111
112- ``` php
112+ ``` json
113113{
114- "token_type": "Bearer",
115- "expires_in": 86400,
116- "access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9...",
117- "refresh_token": "def5020087199939a49d0f2f818..."
114+ "token_type" : " Bearer" ,
115+ "expires_in" : 86400 ,
116+ "access_token" : " eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9..." ,
117+ "refresh_token" : " def5020087199939a49d0f2f818..."
118118}
119119```
0 commit comments