edituraedu/php-dbsc
Composer 安装命令:
composer require edituraedu/php-dbsc
包简介
Preliminary implementation of Device Bound Session Credential standard for PHP 8.4+
README 文档
README
Experimental PHP implementation of Device Bound Session Credentials (DBSC).
Status
This package is completely experimental.
Do not treat it as production-ready security infrastructure yet. APIs, behavior, and defaults may change quickly.
Requirements
- PHP 8.4+
firebase/php-jwt(installed automatically via Composer)
Installation
composer require edituraedu/php-dbsc
What It Provides
EdituraEDU\\DBSC\\DBSCsingleton for DBSC flow handling- Start header emission (
Secure-Session-Registration) - Start endpoint verification (
Secure-Session-Response) - Refresh challenge/verification handling (
Secure-Session-Challenge,Sec-Secure-Session-Id) - Cookie + session guard enforcement
- Optional dependency injection for:
IDBSCLoggerIDBSCInvalidationHandler
Quick Start
<?php use EdituraEDU\\DBSC\\DBSC; DBSC::Initialize(__DIR__ . '/DBSCConfig.json'); // Emit registration header when client has no DBSC cookie yet: if (!DBSC::GetInstance()->HasDBSCCookie()) { DBSC::GetInstance()->SendStartHeader(); }
Start Endpoint
<?php use EdituraEDU\\DBSC\\DBSC; const DBSC_START_REFRESH_FLOW = true; DBSC::Initialize(__DIR__ . '/DBSCConfig.json'); echo json_encode(DBSC::GetInstance()->StartDBSCSession());
Refresh Endpoint
<?php use EdituraEDU\\DBSC\\DBSC; const DBSC_START_REFRESH_FLOW = true; DBSC::Initialize(__DIR__ . '/DBSCConfig.json'); DBSC::GetInstance()->Refresh();
Config
The package reads JSON config via DBSCConfig::LoadFromFile(...).
Start from src/DBSCConfig.json and adjust domains, paths, cookie flags, and endpoint paths for your environment.
Optional Logger / Invalidation Handler
DBSC::Initialize(...) accepts optional custom implementations:
IDBSCLoggerfor structured loggingIDBSCInvalidationHandlerfor custom cleanup when DBSC invalidates a session
If no logger is passed, DBSCLogger is used by default.
Notes
- Header normalization currently tolerates both raw and quoted DBSC header values for compatibility.
- This project is under active iteration, feedback and contributions are welcome!
License
MIT
edituraedu/php-dbsc 适用场景与选型建议
edituraedu/php-dbsc 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 6 次下载、GitHub Stars 达 1, 最近一次更新时间为 2026 年 04 月 29 日, 在 PHP 生态内属于活跃度较高的组件。
它主要适用于以下技术方向: 「security」 「dbsc」 「device-bound-session-credentials」 「tpm」 「device bound session credentials」 等业务场景。在实际项目中,围绕这些方向常见需要落地的问题包括:接口对接、性能调优、并发安全、与既有框架(Laravel / ThinkPHP / Yii / Webman 等)的兼容适配,以及生产环境的日志埋点与稳定性保障。
我们在过去多个企业项目中使用过 edituraedu/php-dbsc 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。
基于 edituraedu/php-dbsc 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。
线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。
承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。
与 edituraedu/php-dbsc 相关的其它包
同方向 / 同关键字的高下载量 PHP Composer 包推荐,方便对比选型:
Provide a way to secure accesses to all routes of an symfony application.
It's a barebone security class written on PHP
Contao CMS integrity check for some files
A PHP security linter to detect insecure functions like var_dump, print_r, and other dangerous functions in your codebase
Cbox SSRF — a hardened, config-driven guard against server-side request forgery for outbound URLs in Laravel. Blocks private/reserved/cloud-metadata targets, pins DNS, and refuses redirects.
A small, framework-agnostic PHP server library for Device Bound Session Credentials (DBSC)
统计信息
- 总下载量: 6
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 1
- 点击次数: 40
- 依赖项目数: 0
- 推荐数: 0
其他信息
- 授权协议: MIT
- 更新时间: 2026-04-29