Download the PHP package kukux/digital-signature without Composer

On this page you can find all versions of the php package kukux/digital-signature. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package digital-signature

Digital Signature for Filament

Latest Version on Packagist Total Downloads License

A Laravel Filament plugin for capturing signatures, issuing X.509 certificates, and embedding cryptographically signed stamps into PDF documents.

Supports: Filament v3, v4 and v5 — Laravel 12 and 13 — PHP 8.2+ (8.3+ on Laravel 13)


Documentation

📖 Read the documentation — the same pages as below, with navigation and search.

Doc Description
Installation Start here. Composer, migrations, plugin registration, admin resource
Configuration All config keys and env variables
Model Setup Signable interface and HasSignatures trait
Filament Components SignaturePad, SignatureColumn, SignatureResource, SignDocumentAction
Signing Workflow Full lifecycle and SignatureManager API
Ad-hoc Signing Implement document signing outside a package resource
Certificates Certificate issuance, CA setup, CFSSL
Signatory Routing Role-bound slots, signing sessions, consent models, multi-signatory documents, Filament version compatibility
Integrating documents 2.0. Make your own documents signable: definitions, guards, the container bindings, the document of record, recipes
Upgrading to 2.0 Every breaking change, with before and after
Security HMAC metadata, machine binding, DB cross-validation, forgery detection
Device Registration Browser signing keys and how they're verified
Desktop Agent Hardware-bound signing via the Kukux Sign Agent

Requirements


Quick Install

The installer asks once, then sets up the config, .env, assets and migration, and registers the plugin and a signature policy on your panels. Every step is logged and safe to rerun. See Installation for the flags and the manual steps.

Re-run php artisan filament:assets after every composer update of this package.

Register the plugin in your panel provider:

This registers:

The floating launcher

Signing is an interruption, not a destination. Rather than adding sidebar items a signatory has to go looking for, the plugin pins a button to every page of the panel; clicking it slides over the documents waiting on them.

While the launcher is on, the inbox page and the Signatures resource stop claiming navigation items — both stay routable, and the slide-over links to them. Keep the launcher and the sidebar entries with SIGNATURE_LAUNCHER_REPLACES_NAV=false.

It won't land on your own floating button. A plugin doesn't own the corner it's dropped into, so before settling the launcher measures what the host app already has pinned there — a FAB, a chat widget, a cookie bar — and stacks itself clear, re-measuring on resize and when widgets mount late. Sidebars and other full-height layout are floated over rather than stacked above. Where the detector guesses wrong, name the widget in launcher.avoid / launcher.ignore; where you already know the answer, set launcher.offset and turn avoid_overlap off.

Position, icon, label, brand colour, offsets, z-index and badge poll interval are all config; see Configuration.


Preparing a Signable Model

Any model whose PDF can be signed must implement Signable and use HasSignatures.


Adding the Sign Action to Your Own Resource

First let the signer register a reusable signature from the built-in Signatures resource. Then add SignDocumentAction to any resource whose model implements Signable.

For controller-driven or custom page flows, see Ad-hoc Signing.


Built-in Signatures Admin Resource

When the plugin is registered, a Signatures resource appears in the sidebar automatically.

Register SignaturePlugin::make() on every Filament panel that should use the package. If a panel discovers or registers SignatureResource without the plugin, Filament can report Plugin [signature] is not registered for panel [admin].

List page: a table of all signature records with thumbnail, signer, status and method. Each row has View (a slide-over with the details), Download and Revoke.

There is no separate View page. Manage signatures in the launcher drawer widens the drawer to show every signature's details, download, revoke, usage history and the PDF templates it can be applied to, without leaving the current page.

Customize appearance:


Multi-Signatory Documents

When a document is signed by roles rather than by whoever opens it — an Accomplishment Report with Prepared by, Attested by and Noted by — declare the roles on the template and let the plugin find the people:

Each person registers their signature once in their own panel. Being tagged on a record is then enough for the document to reach them — the plugin resolves the person, finds their signature, pre-fills the placement, and lists the document in their Awaiting my signature inbox.

If your records tag people who aren't User rows (Personnel, Employee), bind how they become logins once, and slots can name them directly:

Documents generated from a person and a period (a report, a DTR), and any document with its own preconditions, are defined once as a SignableDocument and routed by the package. Once routed, View and Download serve the document of record: every signed version is kept, and each signatory can reopen the exact copy they signed. See Integrating documents.

On consent. By default the plugin never signs for anyone: the signature is always produced in the signatory's own authenticated request, with their own certificate. Truly hands-off signing requires that person to grant a scoped, expiring, revocable authorisation from their own account — and every use of it is audited and notified. See Signatory Routing.


Security Highlights

Feature Default
PKCS#7 cryptographic signature embedded in PDF Always on
DocMDP P=2 — post-signing modification detection Always on
HMAC-signed PNG metadata (tEXt + XMP) Always on
XMP metadata visible in macOS Preview & Windows Explorer Always on
Signer identity (name + email) embedded in PNG Always on
Forgery / screenshot upload rejection Always on
Document integrity hashes (before + after) Always on
Machine binding — DB cross-validation on re-upload Always on
Signature chain hashes across multi-signatory documents Always on
Audit row for every auto-affixed signature Always on
Auto-signing on someone's behalf Off — requires their explicit grant
Machine lock — reject re-upload from different device SIGNATURE_MACHINE_LOCK=true
CRL certificate revocation check SIGNATURE_CRL_ENABLED=true
RFC 3161 trusted timestamp via TSA SIGNATURE_TSA_URL=https://...

For full details see docs/security.md.


Queue

Signing runs asynchronously. Start a queue worker:

To sign synchronously (no queue required):

The action calls embedAndFinalize() directly unless you opt in to queued signing:


All versions of digital-signature with dependencies

PHP Build Version
Package Version
Requires php Version ^8.2
ext-openssl Version *
ext-gd Version *
laravel/framework Version ^12.0 || ^13.0
filament/filament Version ^3.0 || ^4.0 || ^5.0
setasign/fpdi Version ^2.5
tecnickcom/tcpdf Version ^6.7
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package kukux/digital-signature contains the following files

Loading the files please wait ...