lotashinski/apikey-security-classes
Composer 安装命令:
composer require lotashinski/apikey-security-classes
包简介
README 文档
README
Install the latest version with
$ composer require lotashinski/apikey-security-classes
Usage
1. Create users file:
## ./config/service/api_keys.yaml or other users: - user_name: api_admin roles: [ 'ROLE_USER', 'ROLE_ADMIN' ] api_key: qwerty123 ips: - 127.0.0.1 - user_name: api_user roles: [ 'ROLE_USER' ] api_key: bbb123 # if the directive 'ips' is not specified, then it is available from any
2. Configure dependency injection
## ./config/services.yaml services: Grsu\ApiKeySecurity\ApiKeyAuthentication: # arguments: # $strictVerification: false # if there is no need to check every request # $header: X-AUTH-KEY # if you need to change secure header # for create logger tag tags: - { name: monolog.logger, channel: ApiKeyAuthenticator } Grsu\ApiKeySecurity\ApiKeyUserProvider: arguments: # path to users file $pathToUsersConfig: '%kernel.project_dir%/config/service/api_keys.yaml' tags: - { name: monolog.logger, channel: ApiKeyUserProvider }
3. Configure security
### ./config/packages/security.yaml security: # ... providers: # ... api_key_user_provider: id: Grsu\ApiKeySecurity\ApiKeyUserProvider # ... firewalls: # ... api_key: pattern: ^/api/int lazy: true provider: api_key_user_provider custom_authenticator: Grsu\ApiKeySecurity\ApiKeyAuthentication # ... access_control: - { path: ^/api/int, roles: IS_AUTHENTICATED_FULLY }
Example
<?php namespace App\Controller; use Symfony\Bundle\FrameworkBundle\Controller\AbstractController; use Symfony\Component\HttpFoundation\Response; use Symfony\Component\Routing\Annotation\Route; use Symfony\Component\Serializer\Normalizer\NormalizerInterface; class UserController extends AbstractController { #[Route('/api/int/users/me', name: 'api_user_info', methods:['GET'])] public function index(NormalizerInterface $normalizer): Response { $user = $this->getUser(); return $this->json( $normalizer->normalize([ 'class' => get_class($user), 'object' => $user ]) ); } }
For request use X-AUTH-KEY header with api_key from api_users.yaml.
lotashinski/apikey-security-classes 适用场景与选型建议
lotashinski/apikey-security-classes 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 65 次下载、GitHub Stars 达 0, 最近一次更新时间为 2021 年 12 月 03 日, 在 PHP 生态内属于活跃度较高的组件。
我们在过去多个企业项目中使用过 lotashinski/apikey-security-classes 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。
基于 lotashinski/apikey-security-classes 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。
线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。
承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。
统计信息
- 总下载量: 65
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 0
- 点击次数: 8
- 依赖项目数: 0
- 推荐数: 0
其他信息
- 授权协议: proprietary
- 更新时间: 2021-12-03
