l0max/password-history-checker
Composer 安装命令:
composer require l0max/password-history-checker
包简介
Password history checker in laravel
关键字:
README 文档
README
A Laravel package that prevents users from resetting their password to one they have used before. This package ensures that password reuse is restricted by checking against a history of previously used passwords.
Features
- Prevents users from reusing old passwords.
- Customizable password history depth (how many previous passwords to check).
- Simple integration with Laravel's built-in authentication system.
Installation
To install the package, run the following command:
composer require l0max/laravel-password-history
Configuration
After installation, you need to publish the configuration file to customize the package behavior:
php artisan vendor:publish --tag=password-history-checker-config
This will publish a configuration file named password-history-checker.php in your config directory. You can modify the number of passwords to keep in history and customize other settings.
The configuration file looks like this:
return [ 'password_history_count' => 5, // The number of previous passwords to check ];
Usage
Middleware Setup
To prevent users from using previous passwords when resetting their passwords, add the middleware provided by this package to your password reset routes.
In your routes/web.php or routes/api.php:
use L0MAX\PasswordHistoryChecker\Middleware\PreventPasswordReuse; Route::post('/password/reset', 'Auth\ResetPasswordController@reset') ->middleware(PreventPasswordReuse::class);
This middleware will ensure that users cannot reuse any of the last password_history_count passwords they have used.
How it Works
The package checks a user's password against their previous passwords before allowing them to reset it. You can configure how many previous passwords are stored in the history by modifying the password_history_count in the configuration file.
The system uses a password_histories table to store the history of passwords for each user.
Running Migrations
The package includes a migration that adds a table to store the password history. Run the migrations after installing the package:
php artisan migrate
This will create a password_histories table to store user IDs and hashed passwords. This table is used to check previous passwords during the password reset process.
Testing
To run the package's tests:
composer test
License
This package is open-sourced software licensed under the MIT license.
l0max/password-history-checker 适用场景与选型建议
l0max/password-history-checker 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 3 次下载、GitHub Stars 达 1, 最近一次更新时间为 2025 年 01 月 03 日, 在 PHP 生态内属于活跃度较高的组件。
它主要适用于以下技术方向: 「php」 「laravel」 「Laravel-Security」 「laravel-login」 「laravel-package」 「laravel-password」 等业务场景。在实际项目中,围绕这些方向常见需要落地的问题包括:接口对接、性能调优、并发安全、与既有框架(Laravel / ThinkPHP / Yii / Webman 等)的兼容适配,以及生产环境的日志埋点与稳定性保障。
我们在过去多个企业项目中使用过 l0max/password-history-checker 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。
基于 l0max/password-history-checker 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。
线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。
承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。
与 l0max/password-history-checker 相关的其它包
同方向 / 同关键字的高下载量 PHP Composer 包推荐,方便对比选型:
A package to keep a history of all password changes of users
Put users, IP addresses and anonymous browser fingerprints on surveillance and block malicious ones.
Manage fishing and other optional security matters
A Laravel package for automated monitoring of security vulnerabilities and outdated packages in Composer and NPM dependencies.
Laravel package that scans applications (including Livewire) for security vulnerabilities, reports issues with severity levels, and provides remediation guidance and optional automated fixes.
Alfabank REST API integration
统计信息
- 总下载量: 3
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 1
- 点击次数: 13
- 依赖项目数: 0
- 推荐数: 0
其他信息
- 授权协议: MIT
- 更新时间: 2025-01-03