Download the PHP package emacom/bot-shield-core without Composer

On this page you can find all versions of the php package emacom/bot-shield-core. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package bot-shield-core

emacom/bot-shield-core

Framework-agnostic BotShield core: challenge decision, Turnstile verification, signed cookie and bot verification via rDNS. The platform (Magento, WooCommerce, PrestaShop) provides the port implementations and the integration point.

Requirements

Ports

Interface Contract
Port\Config store settings, getHmacSecret() derived from the platform key
Port\Request header, client address behind trusted proxies, URI with query string
Port\CookieJar cookie read and write with Path=/, HttpOnly, Secure, SameSite=Lax
Port\HttpClient form POST, body only for status 200, null in every other case
Port\FilterCounter codes of filters active in the request, no empty values
Psr\SimpleCache\CacheInterface rDNS result cache and circuit breaker counter
Psr\Clock\ClockInterface cookie signature timestamp
Psr\Log\LoggerInterface botshield_* events with context

Classes

Class Role
ChallengeGuard evaluate($context) returns true when the request must get the challenge
ChallengePage widget page HTML, cache-blocking HEADERS, translatable TEXTS
ChallengeResponse redirect() for pages, ajax() for scripts, afterVerification() for the verification endpoint
ChallengeVerification Turnstile token → cookie, result as VerificationResult
Resolver\AjaxDetector X-Requested-With, Sec-Fetch-Dest: empty, Accept: application/json
Turnstile\Verifier token verification via siteverify, fail-open on network error
Verification\Cookie read, validation and issuing of the ts_verified cookie
Verification\Bot X-Verified-Bot header and rDNS with forward confirmation, DEFAULT_BOT_DOMAINS
Resolver\ClientIp client address, /24 or /64 binding prefix, private address detection
CookieSigner, ReturnUrl, Verification\IpRange HMAC signature, safe return URL, CIDR matching

AJAX

Filters reloaded via AJAX get 403 instead of 302. The challenge opens as a modal on the current page.

Platform responsibility Detail
include assets/challenge-interceptor.js on listings no configuration, data arrives in the 403 response
build url with r pointing to the page not the AJAX endpoint, e.g. without from-xhr in PrestaShop
add platform AJAX markers to AjaxDetector::isAjax() from-xhr parameter, admin-ajax action
send Http\Response through the platform response object status, headers, body

Page reload restores filters only when the filter plugin stores them in the URL via pushState.

Tests

Verified on PHP 8.2.1 and 8.5: 184 tests, phpstan level 8 with no errors. Node 22.22: 9 interceptor tests. The Turnstile modal has no automated test.


All versions of bot-shield-core with dependencies

PHP Build Version
Package Version
Requires php Version ~8.2.0||~8.3.0||~8.4.0||~8.5.0
psr/clock Version ^1.0
psr/log Version ^1.1||^2.0||^3.0
psr/simple-cache Version ^1.0||^2.0||^3.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package emacom/bot-shield-core contains the following files

Loading the files please wait ...