thscz/query-signer
Composer 安装命令:
composer require thscz/query-signer
包简介
Creates control hash for specified query values and validate them
README 文档
README
This tool was created as part of my learning and playing with PHP OOP, Composer and PHPUnit.
Usage
composer require thscz/query-signer
Sign
e.g.: file orders.php - User wants to sign "id" value (45623).
require_once 'vendor/autoload.php'; // ... // <a href="/order/45623">Order detail</a> $querySigner = new \THSCZ\QuerySigner\QuerySigner('supersecrtet'); $hash = $querySigner->sign([45623]); echo '<a href="/order/45623/&hash='. $hash .'">Order detail</a>';
Validate
On validation page:
// /order/45623/&hash=xxx require_once 'vendor/autoload.php'; $hash = filter_input(INPUT_GET, 'hash'); $orderId = filter_input(INPUT_GET, 'orderId'); $querySigner = new \THSCZ\QuerySigner\QuerySigner('supersecrtet'); if ($querySigner->validate([$orderId]) { // approved } else { // denied }
Usage with expiration store
You can create hash with TTL (time to live) in seconds. For this option you have to use Expiration Store thats implements ExpirationStoreInterface and stores information about which hash has which expiration.
interface ExpirationStoreInterface { /** * @param $hash string created by QuerySigner * @param $timestamp integer UNIX timestamp value when hash expires * @throws ExpirationStoreException */ public function set(string $hash, int $timestamp): void; /** * @return integer|null UNIX timestamp value when hash expires * @throws ExpirationStoreException */ public function get(string $hash): ?int; /** * Deletes expiration information for hash * @param $hash string created by QuerySigner * @throws ExpirationStoreException */ public function revoke(string $hash): void; }
This package comes with very simple FileExpirationStore that stores information expiration value on file system. Expiration store is second parameter of QuerySigner class.
require_once 'vendor/autoload.php'; // ... // <a href="/order/45623">Order detail</a> $querySigner = new \THSCZ\QuerySigner\QuerySigner('supersecrtet', new \THSCZ\QuerySigner\Store\FileExpirationStore(__DIR__ . '/var/signs')); // hash is now valid for current UNIX timestamp + 60 seconds $hash = $querySigner->sign([45623], 60); echo '<a href="/order/45623/&hash='. $hash .'">Order detail</a>';
Idea for this little tool came to my mind when I was working on some
3rd party exotic system, that was unable to validate that item belonged
really to signed user
thscz/query-signer 适用场景与选型建议
thscz/query-signer 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 13 次下载、GitHub Stars 达 0, 最近一次更新时间为 2018 年 04 月 15 日, 在 PHP 生态内属于活跃度较高的组件。
它主要适用于以下技术方向: 「security」 「url」 「query」 「validate」 「sign」 等业务场景。在实际项目中,围绕这些方向常见需要落地的问题包括:接口对接、性能调优、并发安全、与既有框架(Laravel / ThinkPHP / Yii / Webman 等)的兼容适配,以及生产环境的日志埋点与稳定性保障。
我们在过去多个企业项目中使用过 thscz/query-signer 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。
基于 thscz/query-signer 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。
线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。
承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。
与 thscz/query-signer 相关的其它包
同方向 / 同关键字的高下载量 PHP Composer 包推荐,方便对比选型:
Provide a way to secure accesses to all routes of an symfony application.
Query filtering in your frontend
Easy URL rewrites in your Laravel application
Anax Database Active Record module for model classes.
It's a barebone security class written on PHP
A Laravel helper to detect if the current route/path is active.
统计信息
- 总下载量: 13
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 0
- 点击次数: 6
- 依赖项目数: 0
- 推荐数: 0
其他信息
- 授权协议: MIT
- 更新时间: 2018-04-15