zappzarapp/audit-logger
Composer 安装命令:
composer require zappzarapp/audit-logger
包简介
GDPR-compliant audit logging with injectable encryption, configurable storage, and tamper-proof checksums
README 文档
README
GDPR-compliant audit logging for PHP with injectable encryption, configurable storage, and tamper-proof checksums.
Features
- GDPR compliant - Supports Art. 15, 17, 30, 32, 33
- Injectable encryption - AppEncryption (AES-256-GCM) or DatabaseEncryption
- Tamper-proof - HMAC-SHA-256 checksums with
verify()method - Configurable - Custom table name, optional file logging
- Null Object -
NullAuditLoggerfor environments without audit requirements - Zero dependencies - Only requires
ext-pdo(stdlib) - Both PostgreSQL and MariaDB - Migration SQL included
Installation
composer require zappzarapp/audit-logger
Quick Start
use Zappzarapp\AuditLogger\AuditLogger; use Zappzarapp\AuditLogger\AuditLogEntry; $auditLogger = new AuditLogger( pdo: $pdo, encryptionKey: $_ENV['ENCRYPTION_KEY'], ); // Log a data access event $auditLogger->log(new AuditLogEntry( action: 'user.view', entityType: 'user', entityId: 123, userId: $currentUserId, ipAddress: $request->getClientIp(), userAgent: $request->getUserAgent(), )); // Log authentication $auditLogger->logAuth( action: 'login.success', userId: $userId, ipAddress: $request->getClientIp(), userAgent: $request->getUserAgent(), ); // Log admin action $auditLogger->logAdmin( action: 'role.granted', adminUserId: $adminId, entityType: 'user', entityId: $targetUserId, data: ['role' => 'moderator'], ); // Query logs $logs = $auditLogger->getLogsForEntity('user', 123); $userLogs = $auditLogger->getLogsForUser($userId); // Verify integrity foreach ($logs as $log) { if (!$auditLogger->verify($log)) { // Tampered entry detected! } }
Configuration
use Zappzarapp\AuditLogger\AuditLogger; use Zappzarapp\AuditLogger\Encryption\AppEncryption; use Zappzarapp\AuditLogger\Encryption\DatabaseEncryption; // Full configuration $auditLogger = new AuditLogger( pdo: $pdo, encryptionKey: $_ENV['ENCRYPTION_KEY'], encryption: new AppEncryption(), // default (AES-256-GCM in PHP) tableName: 'audit_logs', // default table name logFilePath: '/var/log/audit.log', // optional file logging (null = disabled) ); // Using database-level encryption (for existing encrypt_text() setups) $auditLogger = new AuditLogger( pdo: $pdo, encryptionKey: $_ENV['ENCRYPTION_KEY'], encryption: new DatabaseEncryption(), ); // Disable audit logging (Null Object pattern) $auditLogger = new NullAuditLogger();
Note: File logging (
logFilePath) does not include log rotation. Configure external rotation (e.g.logrotate) to prevent unbounded file growth.Example
/etc/logrotate.d/audit-logger:/var/log/audit.log { daily rotate 90 compress delaycompress missingok notifempty copytruncate }
Note: The library does not set query timeouts on the injected PDO connection. Configure timeouts at the connection level to prevent indefinite blocking:
// PostgreSQL $pdo->exec('SET statement_timeout = 5000'); // 5 seconds // MariaDB / MySQL $pdo = new PDO($dsn, $user, $pass, [ PDO::ATTR_TIMEOUT => 5, ]);
Database Setup
Apply the migration for your database:
- PostgreSQL:
migrations/postgresql/audit_logs.sql - MariaDB:
migrations/mariadb/audit_logs.sql
Documentation
- GDPR Compliance - GDPR articles covered, purge/retention guidance
- Database Encryption - Migration from DB-level encryption
Development
make install # Install dependencies make test # Run tests make analyse # PHPStan static analysis make cs-check # Code style check make check # All quality checks make check-full # Including mutation testing
License
MIT
zappzarapp/audit-logger 适用场景与选型建议
zappzarapp/audit-logger 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 10 次下载、GitHub Stars 达 0, 最近一次更新时间为 2026 年 02 月 15 日, 在 PHP 生态内属于活跃度较高的组件。
它主要适用于以下技术方向: 「logging」 「security」 「Audit」 「encryption」 「gdpr」 「compliance」 等业务场景。在实际项目中,围绕这些方向常见需要落地的问题包括:接口对接、性能调优、并发安全、与既有框架(Laravel / ThinkPHP / Yii / Webman 等)的兼容适配,以及生产环境的日志埋点与稳定性保障。
我们在过去多个企业项目中使用过 zappzarapp/audit-logger 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。
基于 zappzarapp/audit-logger 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。
线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。
承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。
与 zappzarapp/audit-logger 相关的其它包
同方向 / 同关键字的高下载量 PHP Composer 包推荐,方便对比选型:
Log adding/updating/deleting of elements
Doctrine ORM provider for the auditor audit-log library.
Provide a way to secure accesses to all routes of an symfony application.
A Zend Framework module that sets up Monolog for logging in applications.
PB Web Media Audit Bundle for Symfony
Asynchronous Sentry for Symfony - Fire and forget
统计信息
- 总下载量: 10
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 0
- 点击次数: 31
- 依赖项目数: 0
- 推荐数: 0
其他信息
- 授权协议: MIT
- 更新时间: 2026-02-15