Download the PHP package apigopro/slim-cors-middleware without Composer

On this page you can find all versions of the php package apigopro/slim-cors-middleware. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package slim-cors-middleware

apigopro/slim-cors-middleware

A PSR-15 CORS middleware for Slim Framework 4, requiring PHP 8.5.

Spiritual successor to tuupola/cors-middleware (unmaintained) — same array-based options and behavior, rebuilt as a small, dependency-free PSR-15 middleware with no legacy baggage.

Install

Published on Packagist.

Basic usage

Add this before (outer to) your auth middleware, so preflight OPTIONS requests get answered without ever reaching auth checks or route handlers — browsers send preflight requests without credentials or custom auth headers, so they'd otherwise fail auth for no reason.

How it works

Options

Option Default Notes
origin ['*'] Allowed origins. Exact strings, or patterns with a * wildcard, e.g. 'https://*.example.com'.
methods ['GET', 'POST', 'PUT', 'PATCH', 'DELETE'] Sent as Access-Control-Allow-Methods on preflight responses. A preflight requesting a method outside this list gets rejected with 405 instead. Use ['*'] to allow any method.
headers.allow [] Sent as Access-Control-Allow-Headers on preflight responses. If empty, whatever the browser asked for via Access-Control-Request-Headers is reflected back.
headers.expose [] Sent as Access-Control-Expose-Headers on actual (non-preflight) responses.
credentials false Sends Access-Control-Allow-Credentials: true when enabled. Also makes a configured origin => ['*'] reflect the actual request origin instead of a literal *, since browsers reject the literal wildcard combined with credentials.
cache 0 Seconds for Access-Control-Max-Age on preflight responses. 0 omits the header.
error null function($request, $response, array $arguments): ?ResponseInterface. Called when the origin isn't allowed ($arguments has message, origin) or when a preflight's requested method isn't allowed ($arguments has message, method, allowed_methods). Return a response to override the default 401/405.
response_factory (auto-detects slim/psr7) Any PSR-17 ResponseFactoryInterface.

Wildcard origin patterns

* matches any sequence of characters within a single pattern; it isn't a full glob/regex language, just a simple prefix/suffix/subdomain wildcard.

Migrating from tuupola/cors-middleware

Testing

Covers: pass-through for non-CORS requests, allowed/disallowed origins, wildcard origin patterns (including the credentials + * interaction), preflight short-circuiting, method validation (405 for disallowed methods, wildcard * methods, case-insensitive matching), configured vs. reflected Access-Control-Allow-Headers, Access-Control-Expose-Headers, and custom error callbacks for both origin and method rejections.

License

MIT.


All versions of slim-cors-middleware with dependencies

PHP Build Version
Package Version
Requires php Version ^8.5
psr/http-message Version ^1.1 || ^2.0
psr/http-server-middleware Version ^1.0
psr/http-server-handler Version ^1.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package apigopro/slim-cors-middleware contains the following files

Loading the files please wait ...