Download the PHP package liwenyu/yii2-masked-log without Composer

On this page you can find all versions of the php package liwenyu/yii2-masked-log. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package yii2-masked-log

yii2-masked-log

基于 Yii2 的日志脱敏组件,在写入文件前将涉密字段内容替换为 ***,避免密码、token 等直接落盘。

功能

  1. 涉密字段脱敏:日志内容中的指定字段(如 password、token、user_password)统一替换为 ***
  2. params 开关:通过 params['logMask']['enabled'] 控制是否启用脱敏,便于按环境开关
  3. 可配置脱敏字段:通过 params['logMask']['mask_keys'] 与 mask_vars 定义参与脱敏的字段或参数
  4. 三种脱敏范围:
    • 数组日志:Yii::info($array) 时,数组中与 mask_keys 同名的键会被脱敏(含嵌套)
    • 字符串日志:Params=user_name=xx&user_password=123456 这类 key=value 字符串中,匹配的 value 会变为 ***
    • 上下文变量:error/warning 时输出的 $_GET、$_POST 等会按 mask_keys 与 mask_vars 脱敏
  5. 命名兼容:mask_keys 中配置 user_password 会同时匹配 userPassword(驼峰)
  6. 直接写文件场景:若项目用 file_put_contents 等直接写日志,可调用 MaskedFileTarget::maskLogString($text) 在写入前脱敏

安装

或本地开发时在项目 composer.json 中:

配置

1. params 配置(推荐)

在应用 params 中增加 logMask,组件会主动读取:

2. 将 log 的 FileTarget 换成本组件

在日志组件里把需要脱敏的 target 的 class 改为 MaskedFileTarget,其余配置与 yii\log\FileTarget 一致:

3. 仅用配置、不用 params(可选)

也可以直接在 target 配置里写死开关和字段,不依赖 params:

若同时存在 params 与 target 上的配置,params 会覆盖 target 的 maskEnabled 和 mask_keys;mask_vars 会与 Yii2 默认的 maskVars 合并。

使用示例

写入文件的内容中,上述 password、token 会显示为 ***。

直接写文件的日志(如 request/response 拼接字符串)

若项目中有用 file_put_contents 等直接写日志(不经过 Yii 的 log target),需在写入前对字符串做脱敏。可调用静态方法:

maskLogString() 会读取 params['logMask'](enabled、mask_keys),仅对字符串中的 key=value 形式做替换,与 FileTarget 脱敏规则一致。

404 / error 时上下文脱敏

404 或未捕获异常时,Yii 会把 $_GET、$_POST 等作为上下文写入 error 日志。要脱敏需满足:

  1. 写入该日志的 target 使用 MaskedFileTarget(不要用 yii\log\FileTarget)
  2. params['logMask']['enabled'] 为 true,且 mask_keys 中包含需脱敏的键(如 user_password、password)

组件会对上下文中的 _POST、_GET 等数组按 mask_keys 做整体脱敏,无需在 mask_vars 里逐个写 _POST.user_password(按需可再补)。

功能测试

在已接入本组件的 Yii2 项目中执行:

(需在项目中添加 console/modules/script/controllers/MaskedLogTestController.php 或等效命令并安装本组件。)

测试覆盖三种场景:

  1. 接口请求参数:表单 / JSON 请求体(含 _POST、请求数组中的 password / token)写入日志时脱敏
  2. 接口响应:响应为 JSON 或 XML 时,以数组形式记录的 token、password、secret 等字段脱敏
  3. 程序 error 日志:Yii::error() 中传入的数组里涉密字段脱敏

也可在组件目录下独立运行(需先 composer install):

要求

License

MIT


All versions of yii2-masked-log with dependencies

PHP Build Version
Package Version
Requires php Version >=7.4
yiisoft/yii2 Version ~2.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package liwenyu/yii2-masked-log contains the following files

Loading the files please wait ...