1. Go to this page and download the library: Download kanopi/firewall-laravel library. Choose the download type require.
2. Extract the ZIP file and open the index.php.
3. Add this code to the index.php.
<?php
require_once('vendor/autoload.php');
/* Start to develop here. Best regards https://php-download.com/ */
Event::listen(RequestBlocked::class, function (RequestBlocked $event) {
// …
});
use Kanopi\Firewall\Firewall;
use Kanopi\Firewall\Laravel\Support\HealthReport;
Route::get('/internal/firewall', function (Firewall $firewall) {
$report = (new HealthReport($firewall))->toArray();
return response()->json($report, $report['healthy'] ? 200 : 503);
})->middleware('auth.internal');
// routes/console.php
use Illuminate\Support\Facades\Schedule;
// Move source fetching off the request path. Pair it with `sources.offline: true`
// in global config and the runtime reads cached results and never opens a socket
// — otherwise a cold cache makes a visitor wait on somebody else's HTTP server,
// and an expiry under load sends every concurrent request after the same URL.
Schedule::command('firewall:sources')->hourly()->withoutOverlapping();
// Only needed for the library's own DatabaseHandler. Set `prune_probability: 0`
// on the handler so pruning happens here and nowhere else.
Schedule::command('firewall:log-prune')->dailyAt('03:15');
// Health on a schedule is for the deployments with nowhere to hang a monitor.
// If you have one, prefer the exit code (below) over a log line.
Schedule::command('firewall:health')->everyThirtyMinutes()->onFailure(function () {
// page somebody
});
Route::get('/checkout', function (Request $request) {
if ($request->attributes->get('firewall.mark.suspicious')) {
// extra verification, a slower path, a note on the order
}
});
bash
php artisan firewall:migrate # additive only; never drops or renames
php artisan firewall:sources # warm the caches before traffic arrives
php artisan firewall:doctor # fails the deploy if a rule cannot run