Download the PHP package bitshost/php-crud-api-generator without Composer
On this page you can find all versions of the php package bitshost/php-crud-api-generator. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download bitshost/php-crud-api-generator
More information about bitshost/php-crud-api-generator
Files in bitshost/php-crud-api-generator
Package php-crud-api-generator
Short Description Instant REST API for MySQL/MariaDB with JWT auth, rate limiting, monitoring, and zero code generation
License MIT
Homepage https://github.com/BitsHost/php-crud-api-generator
Informations about the package php-crud-api-generator
PHP CRUD API Generator
Expose your MySQL/MariaDB database as a secure, flexible, REST-like data API.
Auth (API key, Basic, JWT), OpenAPI docs, rate limiting, logging — zero code generation.
Version: 2.1.0 · Upgrade from ≤2.0.1
Design model (read this first)
This package is intentionally a data plane, not an application server and not GraphQL.
| In this API | Outside (your app / JS) |
|---|---|
| list / read / create / update / delete | Joins & related graphs |
| bulk_create / bulk_delete | Multi-step business workflows |
| filter / sort / paginate / count | UI, domain rules, orchestration |
| auth, RBAC, table allow/deny | Compose responses in JavaScript (or upMVC / mobile) |
Fetch tables separately (or with filter=…:in:…), combine on the client.
Guide: Client-side joins.
Features
- Auto-discovers tables and columns
- Full CRUD + bulk create/delete
- Auth: API Key, Basic, JWT (
oauthreserved — not implemented) - Table exposure policy —
allowed_tables/denied_tables - Rate limiting, request logging, optional monitoring
- Filters:
eq,neq,gt,gte,lt,lte,like,in,notin,null,notnull,between - Field selection, multi-column sort, pagination meta
- Per-table RBAC (including filtered
action=tables) - OpenAPI JSON endpoint
- PSR-4 codebase, PHPUnit + PHPStan + CI
Docs: Roadmap
Security warning
Critical: dashboard.html and health.php expose ops/security metrics. Protect them before production.
→ Dashboard security · run php scripts/doctor.php
Installation
Option 1: Library (recommended)
Configs load from ./config or PHPCRUD_CONFIG_DIR.
Option 2: Standalone
Configuration
Older guides said to edit vendor/.../config — that is obsolete.
config/db.php
config/api.php (shape)
Full RBAC examples: config/apiexample.php. Details: CONFIGURATION.md.
Environment (.env)
Copy .env.example → .env. Overrides include:
DB_*, API_AUTH_METHOD, API_KEYS, BASIC_*_PASSWORD, JWT_*,
API_ALLOWED_TABLES, API_DENIED_TABLES (comma-separated).
Production checklist
- [ ] Strong
jwt_secret/api_keys(not examples) - [ ]
auth_enabled=> true - [ ] Explicit
allowed_tables - [ ] Dashboard/health locked down
- [ ]
php scripts/doctor.phpclean enough for your threat model - [ ] DB user least privilege
SECURITY.md
Authentication modes
| Mode | Config | Client |
|---|---|---|
| Off | auth_enabled => false |
— (not for public internet) |
| API Key | auth_method => apikey |
X-API-Key header (prefer over query string) |
| Basic | auth_method => basic |
HTTP Basic |
| JWT | auth_method => jwt |
POST ?action=login then Authorization: Bearer … |
| OAuth | — | Not implemented (always denies) |
API endpoints
Entry: index.php or public/index.php + action=.
| Action | Method | Example |
|---|---|---|
| tables | GET | ?action=tables |
| columns | GET | ?action=columns&table=users |
| list | GET | ?action=list&table=users |
| count | GET | ?action=count&table=users |
| read | GET | ?action=read&table=users&id=1 |
| create | POST | ?action=create&table=users |
| update | POST | ?action=update&table=users&id=1 |
| delete | POST | ?action=delete&table=users&id=1 |
| bulk_create | POST | ?action=bulk_create&table=users |
| bulk_delete | POST | ?action=bulk_delete&table=users |
| openapi | GET | ?action=openapi |
| login | POST | ?action=login (JWT) |
Example curl
Bulk operations
Bulk create
POST ?action=bulk_create&table=users — JSON array. Transactional (rollback on failure).
Bulk delete
POST ?action=bulk_delete&table=users
Count
GET ?action=count&table=users&filter=status:eq:active
Query features (list)
| Param | Description |
|---|---|
filter |
col:op:value or col:value; comma-separated AND |
sort |
Comma-separated; -col = DESC |
page |
1-based (default 1) |
page_size |
Default 20, max 100 |
fields |
Comma-separated columns |
Filter operators
| Op | Example |
|---|---|
eq / bare |
name:eq:Alice or name:Alice |
neq / ne |
status:neq:deleted |
gt gte lt lte |
age:gt:18 |
like |
email:like:%@gmail.com |
in / notin |
status:in:active\|pending |
null / notnull |
deleted_at:null: |
between |
age:between:18\|65 |
Response shape:
OpenAPI
Paste into https://editor.swagger.io/ or use dashboard.html.
Related data (client-side)
More: CLIENT_SIDE_JOINS.md.
Why not GraphQL / server joins by default? Another abstraction layer. With CRUD + filters you can move any data; composition stays in the client where each app can differ.
Security notes
- Auth + rate limit + logging for any shared/public deploy
- Never commit real secrets — use
.gitignore+ examples +.env - Inputs validated; queries parameterized; RBAC + table policy before data access
- Secrets redacted from logs
Logging
Tests
Roadmap
- Client-side joins — current model
- Optional expand/auto-join — only if demand
- OAuth/SSO — if targeting that product shape
- More DB drivers — incremental
- See ROADMAP.md
License
MIT — see LICENSE.