Download the PHP package j1nn0/laravel-encrypted-s3 without Composer

On this page you can find all versions of the php package j1nn0/laravel-encrypted-s3. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package laravel-encrypted-s3

Laravel Encrypted S3

Laravel filesystem support for AWS S3 Client-Side Encryption (CSE) V3. Encryption and decryption are delegated to the AWS SDK for PHP S3EncryptionClientV3 and KmsMaterialsProviderV3.

Client-side encryption happens in the application before data reaches S3 and after encrypted data is downloaded. This is different from S3 server-side encryption such as SSE-S3 and SSE-KMS: those services encrypt data inside S3, whereas this package keeps the plaintext outside S3.

Requirements

The CSE V3 implementation is provided by AWS SDK for PHP 3.382.2 or newer.

Installation

The service provider is registered through Laravel package discovery. Add the disk below to config/filesystems.php.

Configuration

This is a complete disk configuration example:

Unknown keys under the encryption and kms blocks are rejected at disk-construction time. This is deliberate: typos in security-relevant settings fail loudly rather than silently falling back to a default.

These optional AWS SDK client settings are forwarded — endpoint, use_path_style_endpoint, retries, http, http_handler, handler, and debug. Anything else in the disk configuration is ignored rather than passed to the SDK. The common settings may be set under kms for the KMS client; use_path_style_endpoint is S3-only and is rejected under kms, and these common settings are never inherited from the disk. Region and credentials are the exception: the KMS client inherits both from the disk when they are not set under kms. A credentials array takes precedence over key, secret, and token at the same level.

Only Laravel's Flysystem write-default keys — visibility, directory_visibility, retain_visibility, disable_asserts, url, and temporary_url — are forwarded as Flysystem defaults. AWS PutObject parameters placed at the top level of the disk configuration are ignored; options is the only disk-level route for them, while per-call Flysystem Config remains the other route.

root is an S3 key prefix. Encrypted writes, directory markers, and server-side copies send no canned ACL unless the user asks for one through visibility, directory_visibility for makeDirectory(), or an explicit ACL option. Per-call Flysystem Config options override the disk-level options array. If both are set, visibility is applied afterwards and wins over an explicit ACL. copy and move do not retain source visibility and do not issue GetObjectAcl. Before copying, they require the source metadata to contain a complete CSE V3 envelope and no V2 envelope fields; non-CSE sources are rejected before a destination is created. An explicit MetadataDirective other than COPY is rejected so the CSE envelope metadata cannot be discarded. Each copy performs one validation HeadObject in addition to the SDK copy strategy's HeadObject. options['ACL'] is the route for canned ACLs that Flysystem visibility cannot express, such as bucket-owner-full-control. Explicit ACLs can fail on ACL-disabled buckets, so omit them when using Object Ownership BucketOwnerEnforced. throw retains Laravel's normal filesystem exception behavior. options is filtered to this package's CSE-compatible PutObject allowlist: ACL, CacheControl, ContentDisposition, ContentEncoding, ContentType, Expires, GrantFullControl, GrantRead, GrantReadACP, GrantWriteACP, RequestPayer, StorageClass, Tagging, WebsiteRedirectLocation, and ChecksumAlgorithm. Metadata, Body, Bucket, Key, and keys beginning with @ are reserved and rejected or omitted. ContentLength, MetadataDirective, CopySourceSSECustomerAlgorithm, CopySourceSSECustomerKey, and CopySourceSSECustomerKeyMD5 are rejected because the first contradicts the ciphertext body and the others are CopyObject-only. ServerSideEncryption, SSEKMSKeyId, SSECustomerAlgorithm, SSECustomerKey, and SSECustomerKeyMD5 are rejected because server-side encryption is out of scope for CSE, and SSE-C would make objects unreadable through this package. The upstream Flysystem option constant is used only as a test tripwire, not as this allowlist. Disk options outside this allowlist are rejected at configuration time to catch mistakes; per-call runtime Config is broader because it also carries Laravel/Flysystem keys such as visibility and mimetype, so unsupported keys are silently stripped there. ACL cannot be combined with GrantFullControl, GrantRead, GrantReadACP, or GrantWriteACP. The PutObject reference is silent on this combination, but the SDK does not validate it and reported S3 responses reject it with InvalidRequest, so both configuration validation and final request assembly reject it early. Grant options remain valid on their own.

The package sends a canned x-amz-acl only when the user explicitly requests one through visibility, directory_visibility, or options['ACL']. Explicit grant options are likewise sent only when configured. makeDirectory() writes an encrypted trailing-slash marker through the CSE put path and makes one KMS GenerateDataKey call per marker. copy() and move() use server-side S3 copy without retaining source visibility; MetadataDirective is pinned to COPY, and an explicit REPLACE is rejected. visibility() reads the object ACL and works on ACL-disabled buckets because AWS returns the owner's full-control grant. setVisibility() remains an explicit ACL operation and can fail with AccessControlListNotSupported when ACLs are disabled.

kms.key_id is required; there is no unencrypted fallback. The KMS region defaults to the disk region, and KMS credentials default to the disk credentials. The default commitment policy and security profile are the safe V3 settings shown above. encryption_context must be an associative map of string keys and values. The reserved keys aws:x-amz-cek-alg and kms_cmk_id cannot be configured.

allow_decrypt_with_any_cmk is false by default. Setting it to true permits the SDK to try decryption without fixing the KMS key ID to the configured key. This can make key ownership and object provenance less strict, so enable it only for a deliberate migration or compatibility case.

EncryptionOptions exposes the configuration values as typo-safe constants: COMMITMENT_POLICY_FORBID_ENCRYPT_ALLOW_DECRYPT, COMMITMENT_POLICY_REQUIRE_ENCRYPT_ALLOW_DECRYPT, COMMITMENT_POLICY_REQUIRE_ENCRYPT_REQUIRE_DECRYPT, SECURITY_PROFILE_V3, and SECURITY_PROFILE_V3_AND_LEGACY. The first and last are retained for SDK compatibility but rejected during configuration; only the two REQUIRE_ENCRYPT_* policies and V3 are accepted.

Required IAM permissions

The application credentials need, at minimum:

The package's server-side copy and move use one HeadObject to verify the source CSE V3 envelope, and the SDK uses another HeadObject to select the copy strategy. HeadObject uses the s3:GetObject permission. They then use s3:GetObject on the source and s3:PutObject on the destination; there is no separate s3:CopyObject IAM action.

Restrict the S3 resource to the configured bucket and prefix, and restrict the KMS resource to the intended key whenever possible.

Usage

writeStream and readStream are also available, but the AWS SDK CSE V3 implementation is not streaming internally.

Supported filesystem operations

Operation Support Meaning and constraints
put / write Supported with constraints Stored encrypted with CSE. No ACL is sent unless requested through visibility or an explicit options['ACL']; visibility wins when both are set. String bodies are buffered by the SDK and can spill plaintext to a local php://temp file at 2 MiB or larger; watch memory_limit and the temp-file guidance below.
get / read Supported with constraints Returns decrypted plaintext. The complete ciphertext and plaintext are buffered by the SDK, and plaintext at 2 MiB or larger can spill to a local php://temp file.
writeStream Supported with constraints Works, but is not memory-efficient because the SDK CSE implementation is non-streaming. A caller-supplied resource is wrapped as-is, so the SDK does not create an additional plaintext temp-file copy; any spill belongs to the caller's stream.
readStream Supported with constraints The returned resource is backed by decrypted plaintext that the SDK may spill to a local php://temp file at 2 MiB or larger. The resource is detached, so callers must close it.
download / response / serve Supported with constraints Streams decrypted plaintext. Content-Length is measured from the authenticated decrypted stream, and download() and serve() route through response(); the same stream is measured and sent, so one S3 GET serves a response.
exists / fileExists / directoryExists Fully supported Unrelated to encryption.
delete / deleteDirectory Fully supported Unrelated to encryption.
makeDirectory / createDirectory Supported with constraints Writes a CSE-encrypted trailing-slash marker through the put path. It sends no ACL by default, makes one KMS GenerateDataKey call, and accepts an explicitly configured visibility or directory_visibility.
copy Supported with constraints Uses SDK server-side copy, preserving the encryption envelope and original KMS encryption context without re-encryption. It first verifies that the source has every CSE V3 envelope field and no V2 field; non-CSE sources are rejected before the destination is created. It sends no ACL or GetObjectAcl request unless an ACL is explicitly requested; MetadataDirective is fixed to COPY, and REPLACE is rejected.
move Supported with constraints Copy followed by delete. The same CSE V3 source-envelope check and ACL/metadata-directive rules as copy apply; the source is deleted only after a validated copy succeeds. If deletion fails after the copy succeeds, the destination remains and the source is undeleted.
size Supported with constraints Returns ciphertext size, including the 16-byte GCM tag, not plaintext size.
mimeType Supported with constraints Returns the plaintext MIME type detected or supplied at write time. The MIME type is exposed as unencrypted S3 metadata.
lastModified Fully supported Unrelated to encryption.
checksum Supported with constraints Hashes plaintext. It downloads and decrypts the object and therefore incurs KMS and memory costs.
files / directories / allFiles / listContents Fully supported Object key names are not encrypted.
visibility Fully supported Reads the S3 ACL with GetObjectAcl; AWS returns the owner's full-control grant even when bucket ACLs are disabled.
setVisibility Supported with constraints Delegated to Flysystem's S3 adapter, which sends an ACL and fails with AccessControlListNotSupported when bucket ACLs are disabled.
url Not supported Throws UnsupportedOperationException.
temporaryUrl Not supported Throws UnsupportedOperationException.
temporaryUploadUrl Not supported Throws UnsupportedOperationException.

Not supported

Constraints and security notes

Versioning and support policy

From 1.0.0 onward, this package follows Semantic Versioning. The public API is EncryptedS3ServiceProvider, EncryptedS3DiskFactory, Filesystem\EncryptedS3Filesystem, Support\EncryptionOptions, Exceptions\InvalidConfigurationException, Exceptions\UnsupportedOperationException, and the disk configuration array shape. Everything marked @internal — all Support\* classes except EncryptionOptions, plus Flysystem\EncryptedS3Adapter — is outside the compatibility promise and may change in any release. New Laravel and PHP versions are added in minor releases; support for old versions is dropped only in a major release.

Development

Run the default Unit + Feature suite, style check, and static analysis with:

composer lint runs Laravel Pint in test mode. composer analyse runs PHPStan at level 10 against src and tests.

The HTTP integration layer uses the pinned motoserver/moto:5.2.2 container as local S3 + KMS. Start it, run the explicit integration suite, and stop it with:

The fast Unit + Feature suite uses the unchanged InMemoryAws backend and does not need Moto. Moto is a mock, so these integration results do not prove compatibility with real AWS S3/KMS; real AWS remains authoritative.

License

MIT. See LICENSE.


All versions of laravel-encrypted-s3 with dependencies

PHP Build Version
Package Version
Requires php Version ^8.2
ext-openssl Version *
aws/aws-sdk-php Version ^3.382.2
illuminate/filesystem Version ^12.0 || ^13.0
illuminate/support Version ^12.0 || ^13.0
illuminate/contracts Version ^12.0 || ^13.0
league/flysystem Version ^3.29
league/flysystem-aws-s3-v3 Version ^3.29
league/mime-type-detection Version ^1.0
psr/http-message Version ^1.0 || ^2.0
symfony/http-foundation Version ^7.2 || ^8.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package j1nn0/laravel-encrypted-s3 contains the following files

Loading the files please wait ...