Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Create the 'yiisoft/auth-session' package to replace the 'yiisoft/user' package

Open
#137 12 comments 1 reaction 1 assignee View on GitHub

@klsoft-web is already working on this.

Since Sep 4, 2026.

Assessment

This issue has not been assessed yet.

Description

status:ready for adoption

The 'user' term is more relevant to a package that implements the Yiisoft\Auth\IdentityInterface interface, whereas the yiisoft/user package implements various authentication methods via the session:

  • The authenticate(ServerRequestInterface $request) method checks if an identity ID is saved in the session.
  • The login(IdentityInterface $identity) method sets an identity ID in the session.
  • The logout() method removes an identity ID from the session.
    And so on.

The names 'ApiAuth' and 'WebAuth' do not have to be related to the API or web application.
The AuthenticatorInterface is a universal interface for any application that uses sessions.

As the 'yiisoft/user' package contains many misleading names, including its own, the following names were suggested for the new package:

  • 'yiisoft/auth-session' instead of 'yiisoft/user'
  • AuthManager instead of CurrentUser
  • Authenticator instead of ApiAuth and WebAuth

The AuthManager method names are:

  • isAuthenticated() instead of isGuest()

Originally posted by @klsoft-web in https://github.com/yiisoft/docs/discussions/514

Dominant language
PHP
Stars
23
Forks
7
Avg merge
4d 22h
Merged PRs (30d)
1

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from yiisoft/user

All issues in yiisoft/user

Similar issues

More PHP issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.