Skip to main content

Overview

The Password Manager API uses Laravel Sanctum for API token authentication. Sanctum provides a lightweight authentication system for SPAs (single page applications), mobile applications, and simple token-based APIs.

How Sanctum Works

Sanctum offers two authentication methods:
  1. API Token Authentication - Simple token-based authentication for third-party API consumers
  2. SPA Authentication - Cookie-based authentication for first-party single-page applications
For this API, we primarily use API token authentication.

Installation

Sanctum is already included in the project dependencies:
The personal_access_tokens table is created during migration and stores API tokens:

User Model Configuration

The User model is already configured with the HasApiTokens trait:
app/Models/User.php
This trait provides methods for issuing and managing API tokens.

Sanctum Configuration

The Sanctum configuration is located at config/sanctum.php:

Stateful Domains

Domains that receive stateful API authentication:
config/sanctum.php
Add your frontend domain to SANCTUM_STATEFUL_DOMAINS in .env for SPA authentication.

Token Expiration

By default, tokens do not expire:
config/sanctum.php
To set token expiration (in minutes):
.env

Authentication Guards

Sanctum uses the web guard by default:
config/sanctum.php

Issuing API Tokens

To issue API tokens to users, create an authentication endpoint:
routes/api.php

Token Abilities

You can assign specific abilities (permissions) to tokens:

Protecting Routes

IMPORTANT: The current API routes in routes/api.php are NOT protected by authentication. All endpoints are publicly accessible by default.
To secure your API, add the auth:sanctum middleware to protect routes:
routes/api.php
After adding authentication middleware, all requests to these endpoints will require a valid API token.

Making Authenticated Requests

Include the API token in the Authorization header:

Using JavaScript

Using Postman

  1. Select the Authorization tab
  2. Choose Bearer Token as the type
  3. Paste your API token in the Token field

Accessing Authenticated User

In your controllers, access the authenticated user:

Token Management

Revoking Tokens

Revoke all tokens for a user:
Revoke the current token:
Revoke a specific token:

Logout Endpoint

Create a logout endpoint to revoke tokens:
routes/api.php

Checking Token Abilities

If you’ve assigned abilities to tokens, check them in your code:
Or use middleware:

CORS Configuration

For cross-origin requests, ensure CORS is properly configured in config/cors.php:
config/cors.php
Update .env with your frontend URL:

Security Best Practices

  1. Use HTTPS in production - Always transmit tokens over secure connections
  2. Set token expiration - Configure reasonable expiration times for tokens
  3. Implement rate limiting - Protect authentication endpoints from brute force attacks
  4. Rotate tokens - Issue new tokens periodically and revoke old ones
  5. Validate requests - Always validate incoming request data
  6. Store tokens securely - Never expose tokens in URLs or client-side code
  7. Monitor token usage - Track last_used_at in the personal_access_tokens table

Rate Limiting

Add rate limiting to authentication endpoints:
routes/api.php
This limits login attempts to 6 per minute.

Testing Authentication

Test your protected endpoints: