Download the PHP package alvinfadli/access-lock without Composer
On this page you can find all versions of the php package alvinfadli/access-lock. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download alvinfadli/access-lock
More information about alvinfadli/access-lock
Files in alvinfadli/access-lock
Package access-lock
Short Description A lightweight password-protected access gate middleware for Laravel applications.
License MIT
Informations about the package access-lock
access-lock
A lightweight Laravel package that password-protects your application (or specific routes) using a middleware, a JavaScript prompt(), and Laravel session storage.
Not intended for production-grade authentication. Use this as a simple access gate — e.g. for staging environments, internal tools, or early-access previews.
Requirements
| Dependency | Version |
|---|---|
| PHP | ^8.2 |
| Laravel | ^10.0 or ^11.0 |
Installation
1. Install via Composer
The service provider is auto-discovered; no manual registration is needed.
2. Set a Password
Run the Artisan command to set the access password:
You will be prompted to enter and confirm a password. The bcrypt hash is automatically written to your .env file as:
If you cache your configuration, clear it afterwards:
Usage
Web (Monolith / Blade)
Important: always add this middleware inside the
webgroup, never in the global middleware stack. The global stack runs beforeStartSession, so$request->session()would not be available yet and you would get a "Session store not set on request" error.
Laravel 10 — app/Http/Kernel.php
Add it to the web group (after StartSession):
Laravel 11 / 12 / 13 — bootstrap/app.php
Use appendToGroup('web', ...) — not append():
API (Decoupled / SPA / Mobile)
For decoupled setups (e.g. Angular, React, Vue, or mobile apps talking to a Laravel API), use the access.lock.api middleware instead. It is token-based and returns JSON responses rather than redirecting to a Blade view.
1. Protect your API routes
2. Obtain a token
POST the staging password to the built-in unlock endpoint. No authentication is required for this endpoint — it is the entry point.
Success (200):
Wrong password (401):
3. Use the token on subsequent requests
Include the token on every protected API request using one of two headers:
or
The middleware verifies the token against the configured bcrypt hash on every request — no session or cache storage is needed.
How it works
- The client POSTs the password to
/api/access-lock/unlock. - The package verifies it using
access_lock_verify(). - On success, the plain-text password is returned as a token.
- The client stores the token (e.g.
localStorage) and sends it with every subsequent request. AccessLockApiMiddlewarecallsaccess_lock_verify(token)on each request — if it matches the configured hash, the request passes through; otherwise it returns403.
Protect a Route Group (web)
Protect a Single Route (web)
Protect a Route Group (api)
Protect a Single Route (api)
How It Works (Web)
- A visitor hits a protected route.
AccessLockMiddlewarechecks the Laravel session foraccess_lock_unlocked = true.- If not unlocked, the visitor is redirected to
/access-lock. - The unlock page loads and a
window.prompt()dialog appears automatically. - The visitor enters the password and it is submitted via
POST. - If correct, the session flag is set and the visitor is redirected back to the original URL.
- If incorrect, the unlock page reloads with an error message.
How It Works (API)
- A client (SPA, mobile app, etc.) hits a protected API route.
AccessLockApiMiddlewarechecks for a valid token in theAuthorization: BearerorX-Access-Lock-Tokenheader.- If no valid token is found, the request is rejected with a
401or403response. - The client obtains a token by POSTing the password to the
/api/access-lock/unlockendpoint. - On success, the server returns the plain-text password as a token (for convenience in decoupled setups).
- The client stores the token and includes it on every subsequent request.
AccessLockApiMiddlewarecallsaccess_lock_verify(token)on each request — if it matches the configured hash, the request passes through; otherwise it returns403.
Publishing Assets
Publish Config
This copies config/access-lock.php to your application's config/ directory so you can customise it.
Publish Views
This copies the unlock Blade view to resources/views/vendor/access-lock/ for customisation.
Publish Everything
Configuration
After publishing, edit config/access-lock.php:
Bypass Conditions
You can configure query string parameters or request headers that automatically and permanently unlock the session for a visitor — no password prompt is shown.
This is useful for automated tools, CI checks, SSO redirects, or any trusted caller that should never see the lock screen.
Setup
Publish the config and list the query keys / header names you want to act as bypass signals:
Helper Functions
The package provides three global helpers:
Setting Password Programmatically
Middleware Reference
| Alias | Class | Use case |
|---|---|---|
access.lock |
AccessLockMiddleware |
Monolith / Blade apps — session-based, redirects to prompt page |
access.lock.api |
AccessLockApiMiddleware |
Decoupled / API apps — token-based, returns JSON |
License
MIT — see LICENSE.
All versions of access-lock with dependencies
illuminate/console Version ^10.0|^11.0|^12.0|^13.0
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0
illuminate/http Version ^10.0|^11.0|^12.0|^13.0
illuminate/routing Version ^10.0|^11.0|^12.0|^13.0
illuminate/session Version ^10.0|^11.0|^12.0|^13.0
illuminate/support Version ^10.0|^11.0|^12.0|^13.0
illuminate/hashing Version ^10.0|^11.0|^12.0|^13.0