Download the PHP package kaveraa/data-lifecycle without Composer

On this page you can find all versions of the php package kaveraa/data-lifecycle. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package data-lifecycle

Data Lifecycle

Data Lifecycle

Tests Packagist Downloads PHP License

English - Français

The GDPR asks you not to keep personal data longer than needed (article 5.1.e). In real life almost nobody does it: you would have to find the idle accounts, warn the people, disable without breaking anything, leave a way back, then anonymise or delete. And be able to show it.

This package does that journey, with one declaration per entity, for Laravel and for Symfony / Doctrine.


Table of contents

The problem

A database keeps everything, forever, by default. Accounts left behind six years ago are still there, with their address, their name, their history. It is a risk if data leaks, and it goes against the GDPR.

The usual answer is a home-made script, run once, that deletes in bulk. It is frightening, so nobody runs it. This package replaces that script with something you dare to run:

Requirements

Installation

Laravel

The command publishes config/data-lifecycle.php and an example migration. The service provider is found on its own.

Symfony

Add the bundle in config/bundles.php:

Then write config/packages/data_lifecycle.yaml:

Write a policy

Two ways, as you like. Attributes read better, configuration is handier when the rule changes with the environment. If both exist for the same class, configuration wins.

With attributes

An entity can have only a start and an end:

Then say where to look for these classes, in discover:

With configuration

Durations are written in plain words: 3 years, 18 months, 30 days, 48 hours. The ISO 8601 form (P30D) works too.

The columns to add

You only add the columns your policy needs.

Column When it is needed Type
last_active_at always (it is the starting point) date, nullable
lifecycle_warn_stage only with #[WarnBefore] small integer, default 0
lifecycle_warned_at only with #[WarnBefore] date, nullable
disabled_at only with #[DisableFirst] date, nullable
anonymised_at only with #[ThenAnonymise] date, nullable

So a #[KeepFor] + #[ThenDelete] policy needs only the date column. The names can be changed, globally or policy by policy:

Add an index on the date column, and on disabled_at: they carry the queries.

Run the cycle

With Symfony the same commands are bin/console lifecycle:run and bin/console lifecycle:report.

Once a day is enough. Laravel:

Symfony, with cron:

A run is made to be stopped and resumed: --limit bounds every step, and the next run carries on where it stopped.

The first run

On a database that was never cleaned, the whole backlog comes out at once: thousands of rows are already past the deadline. They get their first reminder, then are disabled in the same run, which leaves nobody time to react. Two precautions:

  1. Run lifecycle:report first, and look at the numbers.
  2. Catch up gently: play --step=warn alone for the length of your reminder (30 days if you warn 30 days before), and only then the full command.

Observe mode

This is the front door of the package. Nothing is written, no event is sent, and the report says what would happen:

A row that is very late can show up twice, in warn and in disable: in observe mode nothing is written between the two steps, so the report shows exactly what a real run would do, one step after the other.

Let it run for a few weeks in a scheduled task, watch the numbers settle, then remove --dry-run. Writing can also be blocked from the configuration while you set things up:

As long as this setting is true, lifecycle:run stays in observe mode and says so.

Warn the person

The package sends no email: it tells you when to send one, and you write the message. There are five events, listened to like any event of your framework.

Event When
SubjectWarned a reminder has to go out
SubjectDisabled the row has just been disabled
SubjectAnonymised the personal data is gone
SubjectDeleted the row has been deleted
SubjectReactivated the person came back

No event is sent in observe mode.

When the person comes back

This is the whole point of the grace period: disabling is not deleting.

reactivate() returns false on a row that is already anonymised: what is gone does not come back.

Anonymise

Anonymising instead of deleting keeps your counts right (orders, statistics, invoices) while the person disappears.

Every field gets a strategy. Without one, Strategy::Auto chooses from the name: a field that contains mail gets an address, everything else gets [removed].

Strategy Result
Strategy::Email [email protected], one per row
Strategy::Text Anonymous
Strategy::Redact [removed]
Strategy::EmptyText an empty string
Strategy::Nullify null (the column must accept it)
Strategy::Zero 0
Strategy::YearOnly keeps the year of a date, sets the 1st of January
Strategy::Hash a fingerprint: the value does not come back, but two equal values stay equal

Strategy::Hash helps when you need to know that two rows came from the same person, without knowing who. The replacement texts can be changed in the configuration.

The activity signal

Everything rests on a date you can trust. Writing last_active_at on every request costs one write per request: not acceptable. The package ships a guard that writes only once per window (15 minutes by default).

Laravel, in bootstrap/app.php:

With Symfony the listener is wired by the bundle. The window is set with activity.throttle (in minutes; 0 turns it off).

Watch out for the trap: an automatic login from a cookie, a monitoring call or a scheduled task that touches the table will reset the clock. An account that looks active because a robot goes through it is not active. Pick a deliberate action of the person as the starting point.

Where a row stands

With Laravel, the HasLifecycle trait puts the same answers on the model, plus scopes:

All the options

Option Default Role
dry_run false Blocks every write, everywhere
limit 1000 Rows at most per step and per policy
fields.since last_active_at Column of the last sign of life
fields.warn_stage lifecycle_warn_stage How many reminders were sent
fields.warned_at lifecycle_warned_at Date of the last reminder
fields.disabled_at disabled_at Date of the disabling
fields.anonymised_at anonymised_at Date of the anonymisation
anonymiser.email_domain anonymous.invalid Domain of the replacement addresses
anonymiser.redacted_text [removed] Replacement text
anonymiser.anonymous_name Anonymous Replacement name
anonymiser.pepper the application key Salt of Strategy::Hash
activity.throttle 15 Minutes between two writes of the activity signal
subjects [] The policies written in configuration
discover [] The classes whose attributes are read

What this package does not do

Development

To suggest a change, read the CONTRIBUTING.md guide. See the CHANGELOG for the history of versions.

To report a vulnerability, open a private security advisory rather than a public issue.

License

MIT. See LICENSE.


All versions of data-lifecycle with dependencies

PHP Build Version
Package Version
Requires php Version ^8.2
psr/clock Version ^1.0
psr/event-dispatcher Version ^1.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package kaveraa/data-lifecycle contains the following files

Loading the files please wait ...