Перейти к содержанию

Состав платформы

OAuth2-сервер

Авторизация клиентов API.

Другие решения раздела «Состав платформы»

Установка

Подключите пакет в корне проекта на SkeekS Платформе, затем примените миграции проекта.

composer require skeeks/cms-oauth2-server

Зависимости

  • PHP^7.4|^8.0
  • SkeekS CMS skeeks/cmsSkeekS^6.4 || dev-master

Инструкция из репозитория

SkeekS CMS OAuth2 Server

OAuth 2.1 authorization-code server with PKCE, dynamic client registration, resource indicators and scoped bearer tokens for SkeekS CMS integrations.

Authorization-code exchanges issue rotating refresh tokens. Clients can use grant_type=refresh_token to renew access without another browser login. Refresh-token reuse revokes the complete token family and its access tokens. Raw access and refresh tokens are never stored or displayed.

The authorization server metadata advertises both authorization_code and refresh_token grants. A client registers once, stores its client_id and client_secret, completes PKCE authorization for a configured resource, and then persists the returned refresh token in its operating-system credential store. Every successful refresh returns a replacement refresh token; the old value must be discarded immediately.

The package is transport-neutral. Consumers such as skeeks/cms-mcp register their resources and scopes through the oauth2Server.resources configuration.

See AGENTS.md for architecture, resource registration and mandatory engineering rules for AI agents.

README на GitHub

Поддержка

Вопросы по установке и работе решения можно задать командой SkeekS или завести обращение в репозитории.

Обновления

v1.0.2
v1.0.1
v1.0.0