DI and actions
The facade is the recommended default, not the only way in. Three entry points run the same code: the Authentication facade (shortest), the manager RoundlyConsulting\Auth\AuthenticationManager — the facade’s root, a container singleton — injected through the constructor (same API, explicit dependency, no static calls), and actions in RoundlyConsulting\Auth\Actions\* (single-purpose classes with execute(), for composing into your own actions, jobs and commands).
Inject the manager
use RoundlyConsulting\Auth\AuthenticationManager;
use RoundlyConsulting\Auth\Enums\InvalidationReason;
final class ResetSupportPassword
{
public function __construct(private AuthenticationManager $authentication) {}
public function __invoke(User $user, string $password): void
{
$this->authentication->guard('users')->passwords()->set($user, $password, InvalidationReason::Security);
}
}Call an action
Host-facing actions take the guard name first and refuse an account, invitation or passkey of another guard before anything is written:
use RoundlyConsulting\Auth\Actions\Account\LockAccount;
use RoundlyConsulting\Auth\Actions\Invitations\ResendInvitation;
use RoundlyConsulting\Auth\Actions\Passwords\SetPassword;
use RoundlyConsulting\Auth\Enums\InvalidationReason;
// The raw actions — the same code path; the guard name comes first.
app(SetPassword::class)->execute('users', $user, $temporaryPassword, InvalidationReason::Security);
app(LockAccount::class)->execute('users', $user, 3600);
app(ResendInvitation::class)->execute('users', $invitation); // another guard's invitation → InvitationNotFoundFacade method → action
| Facade method | Action |
|---|---|
attempt() | Login\AttemptPasswordLogin |
requestMagicLink() / consumeMagicLink() | Login\RequestMagicLink / Login\ConsumeMagicLink |
requestEmailOtp() / verifyEmailOtp() | Login\RequestEmailOtp / Login\VerifyEmailOtp |
passkeyLoginOptions() / loginWithPasskey() | Login\BeginPasskeyLogin / Login\CompletePasskeyLogin |
register() | Registration\RegisterAccount |
issueTokens() | Tokens\IssueAccountTokens |
refresh() | Tokens\RefreshTokenPair |
sessions() | Sessions\ListSessions |
logout() / logoutSession() | Sessions\LogoutCurrentSession / Sessions\LogoutSession |
logoutOthers() / logoutEverywhere() | Sessions\LogoutOtherSessions / Sessions\LogoutEverywhere |
invalidate() | Sessions\InvalidateAccountTokens |
disable() / enable() | Account\DisableAccount / Account\EnableAccount |
lock() / unlock() | Account\LockAccount / Account\UnlockAccount |
updateLocale() | Account\UpdateLocale |
activity() | Activity\ListLoginActivity |
prune() | Activity\PruneAuthenticationData |
twoFactor()->status() / start() | TwoFactor\GetTwoFactorStatus / TwoFactor\StartTwoFactorEnrolment |
twoFactor()->confirm() / disable() | TwoFactor\ConfirmTwoFactorEnrolment / TwoFactor\DisableTwoFactor |
twoFactor()->regenerateRecoveryCodes() | TwoFactor\RegenerateRecoveryCodes |
passkeys()->all() / registrationOptions() | Passkeys\ListPasskeys / Passkeys\BeginPasskeyRegistration |
passkeys()->register() / rename() / remove() | Passkeys\RegisterPasskey / Passkeys\RenamePasskey / Passkeys\RemovePasskey |
passwords()->set() / change() | Passwords\SetPassword / Passwords\ChangePassword |
passwords()->requestReset() / reset() | Passwords\RequestPasswordReset / Passwords\ResetPassword |
passwords()->validate() | Passwords\ValidatePasswordPolicy |
email()->sendVerification() / requestVerification() / resendVerification() | Email\SendEmailVerification / Email\RequestEmailVerification / Email\ResendEmailVerification |
email()->verify() | Email\VerifyEmail |
email()->requestChange() / confirmChange() | Email\RequestEmailChange / Email\ConfirmEmailChange |
invitations()->create() / accept() | Invitations\CreateInvitation / Invitations\AcceptInvitation |
invitations()->paginate() / preview() | Invitations\ListInvitations / Invitations\PreviewInvitation |
invitations()->resend() / revoke() | Invitations\ResendInvitation / Invitations\RevokeInvitation |
invitations()->link() | Invitations\SendInvitation (notify: false) |
reauthentication()->sendCode() / passkeyOptions() | Account\SendReauthenticationCode / Account\BeginPasskeyReauthentication |
reauthentication()->confirm() / ensureRecent() | Account\Reauthenticate / Account\EnsureRecentlyAuthenticated |
challenges()->complete() | Challenges\CompleteTwoFactorStep, ConfirmTwoFactorEnrolmentStep, CompletePasskeyStep or CompletePasskeyEnrolmentStep (by method) |
challenges()->passkeyOptions() / passkeyEnrolmentOptions() | Challenges\BeginPasskeyStep / Challenges\BeginPasskeyEnrolmentStep |
challenges()->startTwoFactorEnrolment() | Challenges\StartTwoFactorEnrolmentStep |
- The facade, the manager and the package controllers resolve actions from the container, so all three run the same code.
- Actions tagged @internal are building blocks of these flows, not API: the login pipeline (CompleteFirstFactor, CompleteLogin, EnsureAccountCanLogin, ResolveRequiredSteps, StartLoginChallenge, AssessLoginRisk, DetectNewDevice, RecordLoginActivity), the challenge engine (AdvanceChallenge, FinalizeChallenge, FindActiveChallenge, InvalidateChallenge, RecordChallengeFailure), the four OneTimeTokens actions, VerifyPassword, CreateAccount (replace it through registration.creator), EnforceSessionLimit, BuildAccessTokenRequest and IssueTokenPair (issue through issueTokens(), which also fires TokensIssued).
- Actions take the same DTOs as the facade, from RoundlyConsulting\Auth\DataTransferObjects — PasswordCredentials, SessionContext, CurrentToken, RegistrationData, InvitationData, AcceptInvitationData, ChallengeFactorData, ReauthenticationData, ChangePasswordData, PasswordResetData, EmailChangeData and LocaleData.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.