Download the PHP package loguard/php-runtime without Composer
On this page you can find all versions of the php package loguard/php-runtime. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Informations about the package php-runtime
LoGuard PHP Runtime
LoGuard PHP Runtime connects PHP applications to the LoGuard Security Intelligence Platform.
It collects security-relevant HTTP telemetry inside the application, removes sensitive fields locally, writes events to a local spool, and sends them to LoGuard from a background worker.
The request path does not make network calls to LoGuard.
Requirements
- PHP 7.4 or later
- Composer
- ext-json
- ext-curl
Laravel is supported through Composer package discovery.
Installation
For Laravel applications, the service provider and LoGuard HTTP middleware are registered automatically.
No manual change to app/Http/Kernel.php is required when package discovery is enabled.
Configure LoGuard
Add your project API key and service name to the application environment:
The API key is used by the background delivery worker.
The Laravel request middleware does not use the API key and does not send requests to LoGuard directly.
Run the worker
From the Laravel application root:
In a Laravel application, the worker automatically uses:
The worker also loads the application's .env when Laravel's vlucas/phpdotenv dependency is available.
For production, run the worker periodically or through your process manager.
Example cron entry:
How it works
The default Laravel flow is:
Application requests stay independent from LoGuard availability.
If telemetry processing fails, the application request continues normally.
HTTP security capture
Security capture is enabled by default.
The Runtime can collect bounded context from:
- request path
- query parameters
- JSON request bodies
- vendor JSON content types
- form-urlencoded request bodies
- HTTP response status
- client IP
- authenticated Laravel user identifier
- explicitly selected safe headers
Security capture is not limited to error responses.
Requests returning 200, 302, or another successful status may still contain security-relevant activity.
Sensitive data
Sensitive fields are removed before an event is written to disk.
The Runtime rejects common credential and private-data field names including:
- passwords
- access and refresh tokens
- API keys
- authorization values
- cookies
- sessions
- private keys
- client secrets
- OTP values
- card numbers
- CVV/CVC values
The following headers are not collected:
The Runtime does not automatically capture:
- multipart file bodies
- uploaded files
- arbitrary binary request bodies
- request bodies without a supported content type
Capture is bounded by body size, field count, value size and nesting depth.
Applications using custom names for sensitive data should review their telemetry before production deployment.
Local spool
Events are written to a local file spool before delivery.
Default permissions are:
An event is removed only after successful delivery.
A failed delivery returns the event to the queue for a later attempt.
Laravel configuration
The default configuration works without publishing a config file.
To customize it:
The generated file is:
Useful environment variables include:
Worker-specific options:
HTTPS verification is enabled by default.
LOGUARD_ALLOW_INSECURE_TRANSPORT should not be enabled in production.
Trusted proxies
X-Forwarded-For is used only when the direct peer matches an explicitly configured trusted proxy.
Example:
Do not use broad trusted-proxy ranges unless they match the real network topology.
Non-Laravel applications
The Runtime core is not tied to Laravel.
Non-Laravel applications can use the core capture, event and spool components, but request integration must be added by the application or framework adapter.
Outside a detected Laravel application, the worker defaults to:
Set LOGUARD_SPOOL_PATH when another path is required.
Versioning
The first public Runtime releases use the 0.x version series while support is expanded across PHP frameworks and production environments.
Pin a compatible release range in production.
License
MIT. See LICENSE.
All versions of php-runtime with dependencies
ext-json Version *
ext-curl Version *