Download the PHP package finext/license-client without Composer
On this page you can find all versions of the php package finext/license-client. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download finext/license-client
More information about finext/license-client
Files in finext/license-client
Package license-client
Short Description Client SDK for self-hosted Finext products to activate, verify, and heartbeat against the Finext License Server.
License proprietary
Informations about the package license-client
Finext License Client
Client SDK for self-hosted Finext products to activate, verify, and heartbeat against the Finext License Server. Ships as a Composer package consumed by each product (artiqpay, dating-app, ecommerce, finext-website, finsolvitonline, fixpay, ms2pay, proxypayonline, etc.) — not part of the license-server repo itself, since it has an independent release lifecycle and must never leak server-side secrets or paths into redistributed product code.
Installation
During local development (before this package is published), require it via
a Composer path repository in the host app's composer.json:
Publish the config file:
Configuration
All values are set via .env; see config/license-client.php for the full
list. The essentials:
Local state (installation ID, per-activation secret, encrypted verification
cache, cached public key) is written under storage/app/license/ with
0600 permissions and should stay out of version control.
Security model
Two different guarantees protect two different directions of traffic:
- Server → client (responses): every response is signed with Ed25519 and verified against the pinned/cached public key before any of its contents are trusted. A response that fails verification is treated exactly like a network failure — never surfaced as a real answer. This is a genuine cryptographic authenticity guarantee.
- Client → server (requests): signed with HMAC-SHA256 under one of two
secrets:
- The bootstrap secret (shipped in source, one per product) signs
only the very first
/activatecall. Because it ships with the product, it is necessarily extractable by anyone with the source — it's a deterrence measure, not a real security boundary. - The activation secret is generated by the server on successful
activation, never shipped, and is the real security boundary for every
call afterward (
verify,heartbeat,deactivate).
- The bootstrap secret (shipped in source, one per product) signs
only the very first
This reflects the fundamental limit of licensing a product whose full source is handed to the customer: it deters casual bypass, it does not achieve DRM-level enforcement.
The local cache (EncryptedLocalCache) is encrypted with
sodium_crypto_secretbox using a key derived from product_id +
activation secret, so it fails closed if tampered with, copied to another
installation, or read without the activation secret.
Usage
Activating an installation
Falls back to LICENSE_KEY from config, then interactively prompts if
neither the argument nor config value is set.
Checking license validity (recommended entry point)
check() never throws. It verifies live against the server when reachable;
if the server can't be reached, it falls back to the signed local cache and
applies the offline grace period (grace_period_days from the server, or
LICENSE_DEFAULT_GRACE_PERIOD_DAYS if no cache exists yet).
Gating routes with the middleware
Aborts with 403 and a support message when check()['valid'] is false.
Other operations
Testing this package in isolation
Tests run as plain PHPUnit (no Laravel container bootstrap) — all pure-logic
classes (HmacSigner, ResponseVerifier, EncryptedLocalCache,
GracePeriodPolicy) avoid Laravel facades so they can be exercised directly,
including a golden-vector cross-check of the canonical JSON format against
the license server's own implementation.
Compatibility
PHP ^8.2 with the sodium extension, Laravel (illuminate/support|http|console)
^10, ^11, ^12, or ^13.
All versions of license-client with dependencies
ext-sodium Version *
illuminate/support Version ^10.0|^11.0|^12.0|^13.0
illuminate/http Version ^10.0|^11.0|^12.0|^13.0
illuminate/console Version ^10.0|^11.0|^12.0|^13.0