PHP code example of kanopi / firewall-laravel

1. Go to this page and download the library: Download kanopi/firewall-laravel library. Choose the download type require.

2. Extract the ZIP file and open the index.php.

3. Add this code to the index.php.
    
        
<?php
require_once('vendor/autoload.php');

/* Start to develop here. Best regards https://php-download.com/ */

    

kanopi / firewall-laravel example snippets


'plugins' => [
    [
        'plugin' => \Kanopi\Firewall\Plugins\IpAddress::class,
        'response' => 'allow',
        'weight' => -200,
        'config' => [env('OFFICE_CIDR', '203.0.113.0/24')],
    ],
],

'storage' => [
    'type' => \Kanopi\Firewall\Storage\DatabaseStorage::class,
    'config' => [
        'connection' => ['dsn' => env('DATABASE_URL')],
    ],
],

'presets' => ['wordpress', 'malicious-urls', 'rate-limiting'],

'logger' => [
    'channel' => env('FIREWALL_LOG_CHANNEL', config('logging.default')),
],

Event::listen(RequestBlocked::class, function (RequestBlocked $event) {
    // …
});

use Kanopi\Firewall\Firewall;
use Kanopi\Firewall\Laravel\Support\HealthReport;

Route::get('/internal/firewall', function (Firewall $firewall) {
    $report = (new HealthReport($firewall))->toArray();

    return response()->json($report, $report['healthy'] ? 200 : 503);
})->middleware('auth.internal');

// routes/console.php
use Illuminate\Support\Facades\Schedule;

// Move source fetching off the request path. Pair it with `sources.offline: true`
// in global config and the runtime reads cached results and never opens a socket
// — otherwise a cold cache makes a visitor wait on somebody else's HTTP server,
// and an expiry under load sends every concurrent request after the same URL.
Schedule::command('firewall:sources')->hourly()->withoutOverlapping();

// Only needed for the library's own DatabaseHandler. Set `prune_probability: 0`
// on the handler so pruning happens here and nowhere else.
Schedule::command('firewall:log-prune')->dailyAt('03:15');

// Health on a schedule is for the deployments with nowhere to hang a monitor.
// If you have one, prefer the exit code (below) over a log line.
Schedule::command('firewall:health')->everyThirtyMinutes()->onFailure(function () {
    // page somebody
});

'octane' => ['persist_instance' => true],

'on_boot_failure' => env('FIREWALL_ON_BOOT_FAILURE', 'throw'),

'global' => ['

Route::get('/checkout', function (Request $request) {
    if ($request->attributes->get('firewall.mark.suspicious')) {
        // extra verification, a slower path, a note on the order
    }
});

'global' => [
    'mode' => 'lockdown',
    'lockdown_allow' => ['203.0.113.0/24'],
],
bash
composer vendor:publish --tag=firewall-config
php artisan firewall:doctor
bash
php artisan vendor:publish --tag=firewall-views
bash
php artisan firewall:block 203.0.113.9                        # an hour
php artisan firewall:block 203.0.113.9 --duration=0 --reason="Scraping /api"
php artisan firewall:block 203.0.113.9 --duration=86400 --force   # replace an existing block
bash
php artisan firewall:unblock 203.0.113.9
php artisan firewall:unblock 203.0.113.0/24 --dry-run
php artisan firewall:unblock --all
bash
php artisan firewall:migrate                 # additive only; never drops or renames
php artisan firewall:sources                 # warm the caches before traffic arrives
php artisan firewall:doctor                  # fails the deploy if a rule cannot run
bash
php artisan firewall:health --json
json
{
    "healthy": true,
    "mode": "exception",
    "configured_mode": "exception",
    "mode_overridden": false,
    "panic_switch": { "active": false, "mode": null, "path": null, "problem": null },
    "locked_down": false,
    "failed_rules": [],
    "sleeping_rules": [],
    "degraded_backends": [],
    "errors": [],
    "warnings": []
}