Download the PHP package codectrl-sro/apollo without Composer
On this page you can find all versions of the php package codectrl-sro/apollo. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Informations about the package apollo
Apollo
A PSR-7 / PSR-15 web framework for PHP 8.3+, built on League Route and League Container, with Doctrine ORM, Twig and Laminas Form.
- Documentation: https://deepwiki.com/CodeCTRL-sro/apollo
- Upgrading: UPGRADE.md
- Changes: CHANGELOG.md
Quickstart
1. Install
Some capabilities are optional and declared as suggest rather than require, so a
JSON-only service is not forced to install an image stack. Add what you use:
ext-redis, ext-gd, ext-imagick, ext-exif, ext-soap and ext-simplexml are
likewise optional — see the suggest block in composer.json.
2. Lay out the project
3. Front controller
4. Minimal route config
5. Environment
Copy .env.example to .env and fill it in. Read values through Env,
never $_ENV directly:
Routing
Routes are nested arrays of paths. A path may carry methods, child paths, and requirements that child paths inherit.
Middleware
Reference middleware by alias, by group, or by class name. Aliases take
alias:arg,arg parameters.
| Alias | Class | Parameters |
|---|---|---|
auth |
AuthMiddleware |
auth_method |
can |
PermissionMiddleware |
module,right |
can_group |
PermissionGroupMiddleware |
group |
csrf |
CsrfMiddleware |
— |
headers |
SecurityHeadersMiddleware |
— |
throttle |
ThrottleMiddleware |
limit,window_seconds |
fields |
FieldsMiddleware |
— |
content_type |
ContentTypeMiddleware |
mime |
required_headers |
HeadersMiddleware |
— |
Register your own and compose groups from them:
Security defaults
| Concern | Where | Default |
|---|---|---|
| Session cookie | SessionGuard, applied at boot |
SameSite=Lax, HttpOnly, Secure on HTTPS, strict session ids |
| Response headers | SecurityHeadersMiddleware |
nosniff, Referrer-Policy, X-Frame-Options; CSP/HSTS opt-in |
| CSRF | CsrfMiddleware, csrf_field() |
Per-form tokens, constant-time comparison |
| Encryption | CryptHelper |
AES-256-GCM, authenticated |
| Rate limiting | ThrottleMiddleware |
Opt-in per route, Redis-backed |
| Open redirects | RedirectGuard |
Local paths inside the basepath only |
| Proxies | RemoteAddressHelper::fromOptions() |
Forwarded headers only from routing.trusted_proxies |
Error output is bounded by route.debug: outside debug mode a failure renders the
status and reason phrase, and nothing else.
Development
composer cs and composer rector currently report the whole codebase. The rules are
configured, but the sweep is intentionally left as its own commit so that feature diffs
stay reviewable; CI runs both as advisory steps.
New PHPStan findings fail the build. Existing ones are frozen in phpstan-baseline.neon
— shrink it with composer stan:baseline after fixing a batch.
Used packages
Doctrine ORM · League Container / Route · Monolog · Guzzle · Twig · Laminas (Form, I18n, ServiceManager, Diactoros, HttpHandlerRunner) · Firebase PHP-JWT · PHPMailer · Intervention Image · Symfony Cache · Gedmo Doctrine Extensions
License
MIT
All versions of apollo with dependencies
ext-curl Version *
ext-openssl Version *
ext-date Version *
ext-dom Version *
ext-hash Version *
ext-iconv Version *
ext-json Version *
ext-mbstring Version *
ext-pdo Version *
ext-reflection Version *
ext-fileinfo Version *
doctrine/doctrine-module Version ^6.3
doctrine/orm Version ^3.3
gedmo/doctrine-extensions Version ^3.19
laminas/laminas-diactoros Version ^3.5
laminas/laminas-mvc-i18n Version ^1.9
laminas/laminas-i18n Version ^2.29
laminas/laminas-servicemanager Version ^3.23
laminas/laminas-httphandlerrunner Version ^2.11
league/container Version ^4.2
league/route Version ^5.1
monolog/monolog Version ^3.8
guzzlehttp/psr7 Version ^2.7
guzzlehttp/guzzle Version ^7.9
twig/twig Version ^3.20
beberlei/doctrineextensions Version ^1.5
fullpipe/twig-webpack-extension Version ^4.0
firebase/php-jwt Version ^6.11 || ^7.1
phpmailer/phpmailer Version ^6.9
voku/anti-xss Version ^4.1
symfony/cache Version ^5.4
intervention/image Version ^3.6
league/oauth2-client Version ^2.9
league/oauth2-google Version ^4.1