For Developers
Support for frontend users has been removed from version 13.
API Notes
This section documents public APIs that extension developers may use or override.
ApplicationFactory
Application
Pass the current PSR-7 request as the third argument whenever one is available. The factory uses
the request to derive the OAuth redirect URI via Normalized. If no request is passed (e.g.
in CLI commands or early-boot contexts), $_ is used as a last resort — the redirect URI
is constructed but never used in an actual OAuth flow in those contexts.
The returned Auth0 instance is wired with Auth0SDKStore for both
session and transient storage. cookie defaults to TYPO3's encryption key, cookie
follows $GLOBALS, and cookie is Lax.
Subclasses overriding build to provide a custom Auth0SDKContract must
not call session_ directly or indirectly — doing so re-introduces the conflict with
the TYPO3 Install Tool's File (see Session Storage).
TokenUtility
Token
Builds a signed JWT for the OAuth state callback. The issuer (request host) must be passed
explicitly. Derive it from the request: $request->get.
Token
Verifies a callback token. Pass the same issuer that was used when the token was built.
Note
The former get / set methods have been removed in version 14.0.0.
The issuer is no longer stored as object state; pass it at call time instead.
ModeUtility
Mode
Returns Mode when the request is a backend request, otherwise
Mode. The method no longer reads from $GLOBALS;
pass the request explicitly.
Mode
When $mode is null and a $request is provided, the mode is derived from the request.
When neither is provided, the method returns false (unknown mode is not backend).
Note
The constant UNKONWN_ (typo) was renamed to UNKNOWN_ in version 14.0.0.
UserRepository
User
Inserts a user record into the database. Starting with version 14.0.0, this method returns the
uid of the newly created record. Custom implementations overriding this method must update
their return type to int.