Download the PHP package andrewthecoder/arcmvc without Composer

On this page you can find all versions of the php package andrewthecoder/arcmvc. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package arcmvc

Arc

A lightweight, modern PHP MVC framework. Small core, batteries included, built for PHP 8.4+.

Principles

Requirements

Quick Start

Or add Arc to an existing project:

Visit http://localhost:8080

Environment Setup

Copy .env.example to .env and adjust values:

Arc includes a built-in .env loader. Load it early in your bootstrap:

Environment variables are available via $_ENV and getenv(). Existing env vars are never overwritten.

Routing

Define routes in routes/web.php:

Route groups with prefix and middleware:

Controllers

Controllers extend Arc\Support\Controller and receive the current request via setRequest():

Controllers are resolved through the DI container, enabling constructor injection.

Views and Templates

Views live in resources/views/ and use .phtml files:

Layouts use yield() for content:

XSS Escaping

Use e() to escape user-supplied data:

Content and named sections yielded via yield() are raw by design (they contain trusted template HTML). Always escape user data with e().

CSRF Protection

Include a CSRF token in forms:

The CsrfMiddleware validates the token automatically on POST, PUT, PATCH, and DELETE requests.

Partials

Middleware

Immutable middleware examples

Example: add security headers without mutating the original Response

Example: attach request-scoped data immutably

Register global middleware in your bootstrap:

Security Headers

SecurityMiddleware sets headers with configurable defaults:

CSRF

CsrfMiddleware uses the double-submit cookie pattern with a SameSite=Strict, HttpOnly cookie (marked Secure automatically on HTTPS requests). The token is attached to the request as the _csrf_token attribute and is automatically passed to views rendered via Controller::view(), so csrfField() works without manual wiring.

Rate Limiting

RateLimitMiddleware tracks requests per client IP with configurable limits:

Behind a reverse proxy, pass the proxy IPs as trustedProxies so the client is read from X-Forwarded-For (it is ignored from untrusted peers, preventing spoofing). For stricter per-route limits, supply a keyResolver:

The default in-memory store is per-process; for multi-process or distributed deployments, implement RateLimitStoreInterface with Redis or a database backend.

HTTP Request & Response

Compatibility note (PHP 8.5): There is a core bug where return clone($this)->method() may mutate $this instead of the clone. Arc’s with* implementations use a two-statement pattern ($new = clone $this; $new->method(); return $new;) to avoid this. If you implement your own immutable-style methods, avoid one-line clone-chains on PHP 8.5.

Query Builder

Arc\Database\QueryBuilder provides a fluent interface for building SQL queries. All identifiers are validated against SQL injection.

Database and Models

Configure the database connection in config/database.php, then extend the Model:

Available methods:

Fluent queries via query():

Column names in where(), create(), and update() are validated against a strict regex (/^[a-zA-Z_][a-zA-Z0-9_]*$/) to prevent SQL injection. Invalid identifiers throw InvalidArgumentException.

Validation

Available rules: required, string, integer, numeric, email, url, boolean, min, max, between, same, different, in, not_in, alpha, alpha_num, regex, date.

The regex rule uses ~ as delimiter (supports patterns containing /):

Custom error messages:

Session

File Uploads

Configuration

Config files live in config/ and return arrays:

Access via the application:

DI Container

The container supports explicit bindings, singletons, and auto-wiring:

Constructor parameters with class types are resolved from the container. Scalar parameters require defaults or explicit bindings.

Error Handling

In production (APP_DEBUG=false), errors are logged and a generic error page is shown. In debug mode, full stack traces are displayed.

Database errors are wrapped in DatabaseException to prevent sensitive SQL and table names from leaking.

CORS

CorsMiddleware handles cross-origin requests and preflight:

HTTP Method Override

Browser forms only support GET and POST. Arc supports method spoofing via a hidden _method field or the X-HTTP-Method-Override header:

Or via API header:

Only POST requests can be overridden to PUT, PATCH, or DELETE. Use getOriginalMethod() to see the actual HTTP method.

Console Commands

License

MIT, see LICENSE.

Contributing

PRs welcome. Please open an issue first for major changes. See CONTRIBUTING.md for details.

Security

See SECURITY.md for how to report vulnerabilities.


All versions of arcmvc with dependencies

PHP Build Version
Package Version
Requires php Version >=8.4
ext-pdo Version *
psr/container Version ^2.0
psr/log Version ^3.0
symfony/filesystem Version ^8.1
symfony/process Version ^8.1
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package andrewthecoder/arcmvc contains the following files

Loading the files please wait ...