A PHP library supporting EVE Online SSO v2 for web applications including JWT signature verification.
To install the library via Composer, execute:
composer require tkhamez/eve-ssoThese examples do not include error handling. Most methods throw exceptions which should be caught.
// Initiate the provider object.
$provider = new Eve\Sso\AuthenticationProvider(
[
// Required.
'clientId' => 'your-EVE-app-client-ID',
'clientSecret' => 'your-EVE-app-secret-key',
'redirectUri' => 'https://your-callback.url',
// Optional. If you do not provide all URLs, a request will be made
// to the metadata URL to get them.
'urlAuthorize' => 'https://login.eveonline.com/v2/oauth/authorize',
'urlAccessToken' => 'https://login.eveonline.com/v2/oauth/token',
'urlRevoke' => 'https://login.eveonline.com/v2/oauth/revoke',
'urlKeySet' => 'https://login.eveonline.com/oauth/jwks',
'issuer' => 'https://login.eveonline.com',
'urlMetadata' => 'https://login.eveonline.com/.well-known/oauth-authorization-server',
],
// Optionally, add all required scopes.
['esi-mail.read_mail.v1', 'esi-skills.read_skills.v1'],
// Optionally, use your own HTTP client.
httpClient: new GuzzleHttp\Client(),
// Optionally add a logger to log exceptions that are caught from libraries
// (any class implementing Psr\Log\LoggerInterface, the example uses monolog/monolog
// which is not included in this package).
logger: new Monolog\Logger('SSO', [new Monolog\Handler\StreamHandler('/path/to/logfile')])
);
// Optionally disable signature verification.
$provider->setSignatureVerification(false);// Login URL
session_start();
$_SESSION['state'] = $provider->generateState();
$loginUrl = $provider->buildLoginUrl($_SESSION['state']);
header("Location: $loginUrl");// Callback URL
session_start();
$eveAuthentication = $provider->validateAuthenticationV2(
$_GET['state'] ?? '',
$_SESSION['state'] ?? '',
$_GET['code'] ?? '',
);
unset($_SESSION['state']);
$characterId = $eveAuthentication->getCharacterId();
$refreshToken = $eveAuthentication->getToken()->getRefreshToken();
$accessToken = $eveAuthentication->getToken()->getToken();
$expires = $eveAuthentication->getToken()->getExpires();
// ... store the token data somewhere together with the character ID.// Refreshes access token, if necessary.
$existingToken = new League\OAuth2\Client\Token\AccessToken([
'refresh_token' => $refreshToken,
'access_token' => $accessToken,
'expires' => $expires,
]);
$validToken = $provider->refreshAccessToken($existingToken);docker build --tag eve-sso .
docker run -it --mount type=bind,source="$(pwd)",target=/app --workdir /app eve-sso /bin/sh