Download the PHP package assertchris/cloudflare-security-rule-sync without Composer

On this page you can find all versions of the php package assertchris/cloudflare-security-rule-sync. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package cloudflare-security-rule-sync

cloudflare-security-rule-sync

Your app has routes you want the world to hit and routes that should stay locked down. This package figures out the first group and tells Cloudflare to block everything else.

We collect your routes, Folio pages, public files, and any extra paths you configure, then build an allowlist expression and push it to Cloudflare's Rulesets API. Everything not on the list gets blocked at the edge before it even touches your server.

Installation

Then publish the config:

Getting a Cloudflare API Token

You'll need a token with permission to edit your zone's custom rules.

  1. Go to dash.cloudflare.com → My Profile → API Tokens → Create Token
  2. Choose Create Custom Token
  3. Under Permissions, add: Zone → Custom Rules → Edit
  4. Under Zone Resources, set: Include → Specific zone → (your zone)
  5. Create the token and copy it — you won't see it again

Here's something important: Cloudflare requires the custom ruleset to exist before the API can update it. Create at least one placeholder rule in the dashboard first. We'll find the rule matching your configured description and update it — or append a new one if it doesn't exist.

Configuration

Add these to your .env:

Your zone ID is on the overview page for your domain in the Cloudflare dashboard.

The full config (after publishing) looks like this:

rule.description — we match this against the Cloudflare rule's description to find and update the existing rule rather than appending a new one on every sync. Keep it unique per app.

rule.action — what Cloudflare does when a request doesn't match. Defaults to block. Other options: challenge, js_challenge, managed_challenge, log, bypass.

rule.ignorable_paths — paths we exclude from the allowlist even if they show up in your routes. Wildcards work here. Dusk and Boost paths are already excluded by default.

rule.forced_allow_paths — paths we always include in the allowlist even if they don't show up in your routes. Wildcards work here too.

rule.hostnames — when set, we wrap the expression with an http.host in {...} check. Handy if your zone serves multiple apps.

Usage

Let's preview the generated expression without pushing anything:

It'll print the rule description and the full expression — a good way to see what we'd push before it actually goes anywhere.

When you're happy, push it:

The command collects paths from three places:

Route parameters become wildcards — /users/{id}/posts/{postId} becomes /users/*/posts/*. We collapse duplicates, strip redundant entries, and if the expression hits Cloudflare's 4000-character limit, we condense it further by collapsing paths that are covered by their wildcard parents.

Running on Deploy

The typical setup is a single line in your deployment pipeline:

The sync is idempotent. If a rule with the matching description already exists, we update it. If not, we append a new one to your ruleset.

Credits

Inspired by nexxai/laravel-cfcache. This package does one thing — security rule sync — and uses the current Rulesets API instead of the deprecated Firewall Rules API.


All versions of cloudflare-security-rule-sync with dependencies

PHP Build Version
Package Version
Requires php Version >=8.3
illuminate/console Version ^13
illuminate/support Version ^13
illuminate/http Version ^13
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package assertchris/cloudflare-security-rule-sync contains the following files

Loading the files please wait ...