Skip to content

Add API key and legacy authentication alongside OIDC - #18

Merged
lennartvava merged 1 commit into
developfrom
feature/api-key-auth
Oct 1, 2026
Merged

lennartvava merged 1 commit into
developfrom
feature/api-key-auth

Conversation

@lennartvava

Copy link
Copy Markdown
Contributor

Summary

Add API key authentication and restore the v3 configuration path alongside OIDC.

  • Add ApiKeyConfiguration to authenticate using apiKey and applicationId headers.
  • Add LegacyConfiguration for clients that manage their own authentication.
  • Introduce a shared configuration interface and require a token cache only for OIDC.
  • Preserve existing OIDC configuration signatures, protected property types, and token-provider behavior.
  • Document the upgrade path from v3 to v4.3.

Validation

  • 35 tests passed with 105 assertions, including OIDC subclass compatibility, cached Bearer authentication, API key headers, and legacy header preservation.
  • Coding standards, static analysis, mess detection, and duplicate-code checks passed.
  • Verified Composer dependency resolution with the local checkout.

Targets release 4.3.0. Existing v4 OIDC consumers require no code changes.

@lennartvava
lennartvava requested a review from zero2one October 1, 2026 13:14
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Coverage report for commit: 780b82a
File: build/logs/clover.xml

Summary - Lines: 86.16% | Methods: 93.75%
FilesLinesMethodsBranches
src/Client/Token
   OidcTokenProvider.php--100.00%

🤖 comment via lucassabreu/comment-coverage-clover

@lennartvava
lennartvava merged commit 065e5aa into develop Oct 1, 2026
3 checks passed
@lennartvava
lennartvava deleted the feature/api-key-auth branch October 1, 2026 13:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants