Download the PHP package mohamedmohamedhekal/oncegate without Composer
On this page you can find all versions of the php package mohamedmohamedhekal/oncegate. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download mohamedmohamedhekal/oncegate
More information about mohamedmohamedhekal/oncegate
Files in mohamedmohamedhekal/oncegate
Package oncegate
Short Description Stripe-style Idempotency-Key middleware for Laravel APIs with response replay and concurrent locks
License MIT
Homepage https://github.com/mohamedhekal/oncegate
Informations about the package oncegate
OnceGate
Stripe-style Idempotency-Key middleware for Laravel APIs. Store the first response, replay safe retries, reject payload mismatches, and return 409 while a request with the same key is still in flight.
Update badge URLs after publishing the GitHub repository.
Problem
Mobile apps, payment clients, and flaky networks retry POST/PUT requests. Without idempotency keys, those retries create duplicate orders, charges, or shipments.
Features
Idempotency-Keyheader handling (name configurable)- Request fingerprinting (method + path + body hash, optional user scope)
- Response replay with
Idempotent-Replayed: true - Fingerprint mismatch →
422 - In-flight conflict →
409 - Cache driver (default) and database driver
- Optional required-key mode
oncegate:purgefor expired database records
Requirements
- PHP 8.2+
- Laravel 11 or 12
Installation
Quick start
Client:
First response is executed normally. Retries with the same key and body receive the stored response and header Idempotent-Replayed: true.
Alias middleware name: idempotency (same class).
Configuration
| Key | Default | Meaning |
|---|---|---|
header |
Idempotency-Key |
Incoming header name |
methods |
POST, PUT, PATCH, DELETE | Methods that participate |
required |
false |
Abort 400 when header missing |
driver |
cache |
cache or database |
ttl |
86400 |
Stored response lifetime (seconds) |
lock_ttl |
60 |
Processing marker TTL (cache) |
fingerprint.include_user |
true |
Scope keys per authenticated user |
Architecture
See docs/architecture.md.
Testing
Security notes
- Keys are scoped by user when
fingerprint.include_useris enabled. - Do not log raw idempotency payloads if they contain secrets—pair with a redaction package if needed.
- Prefer Redis cache in production for atomic
addsemantics under load.
License
MIT — see LICENSE.
Credits
Mohamed Hekal.
All versions of oncegate with dependencies
illuminate/support Version ^11.0|^12.0
illuminate/http Version ^11.0|^12.0
illuminate/cache Version ^11.0|^12.0
illuminate/database Version ^11.0|^12.0
illuminate/console Version ^11.0|^12.0
illuminate/routing Version ^11.0|^12.0