Download the PHP package olipayne/guzzle-web-bot-auth-middleware without Composer

On this page you can find all versions of the php package olipayne/guzzle-web-bot-auth-middleware. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package guzzle-web-bot-auth-middleware

Latest Stable Version Total Downloads License CI

Guzzle Web Bot Auth Middleware

This package signs outbound Guzzle requests with Ed25519 HTTP Message Signatures. It lets an automated client prove continuity of identity without relying only on a spoofable User-Agent, changing cloud IP ranges, or a shared secret negotiated with every origin.

The receiving server still decides whether to trust or authorize that identity. A valid signature proves control of a key published by the claimed Signature Agent; it does not prove that the bot is safe or that a request is authorized.

Standards status

The implementation follows:

RFC 9421 is stable. The Web Bot Auth protocol is an active Standards Track Internet-Draft and can change before it becomes an RFC. The exact draft revision above is therefore part of this package's compatibility contract; Renovate and the scheduled integration test help surface ecosystem drift, but consumers should still review release notes before upgrading.

For each request the middleware currently emits:

Covering the method, path, and query as well as the required authority narrows replay scope. If the request already has a Content-Digest field, the middleware covers it too. It does not calculate a digest or buffer request bodies for you.

Deployment compatibility

Cloudflare's deployed verifier and public documentation currently use the older bare-string Signature-Agent field, while the current Internet-Draft requires the dictionary form shown above. Use the standards-current directory default for new integrations. If a Cloudflare endpoint returns 400 because it has not adopted the current draft yet, select the explicit cloudflare_legacy mode as a temporary compatibility bridge:

That mode emits a bare Structured Fields string and covers "signature-agent" without the current draft's key parameter. It is intentionally opt-in and should be removed from application configuration when the target verifier supports the current draft.

Requirements

Installation

Generate an Ed25519 key

From your application root:

The script creates:

To convert an existing raw 32-byte Ed25519 public key encoded as base64:

Publish the key directory

With the default directory discovery type, publish a JWKS at:

Serve it over HTTPS with Content-Type: application/http-message-signatures-directory+json:

The current draft permits a directly resolved directory without a signed directory response. A signature is still needed when redistributed key material is expected to prove its association with the directory URL. This package signs requests; serving and signing the directory response remains the operator's responsibility.

Usage

Pass the private key or its file path, the JWK Thumbprint, and the Signature Agent origin:

The exact legacy well-known URL is also accepted and normalized to its origin, so existing configuration can migrate without changing the stored value.

Discovery types and optional settings

Constructor arguments after the three required values are intentionally optional and retain their original positions:

  1. tag defaults to web-bot-auth. A custom value is retained for backwards compatibility but opts the signature out of the Web Bot Auth profile.
  2. expiresInSeconds defaults to 300. The draft recommends no more than 24 hours; shorter lifetimes reduce replay exposure.
  3. signatureLabel defaults to sig.
  4. discoveryType defaults to directory; current-draft values are directory, jwks_uri, and cimd. The transitional cloudflare_legacy value is also available for the deployed compatibility case described above.
  5. clock is an optional callable for deterministic testing and must return an integer Unix timestamp.

For a direct JWKS URL, select jwks_uri explicitly:

This emits Signature-Agent: sig="https://agent.example/keys.json";type=jwks_uri as required by the current draft.

Upgrading from 1.x

Version 2.0 corrects the RFC 9421 wire format and adopts the current dictionary form of Signature-Agent. This is intentionally a major release because verifiers or tests that depended on the old malformed/legacy fields will observe different headers.

The constructor's first five positional arguments remain compatible. The default signature label also remains sig. The material changes are:

If a 1.x application targets Cloudflare's currently deployed legacy verifier, migrate it with cloudflare_legacy first, verify the endpoint accepts the new RFC 9421 serialization, and move to directory once that endpoint supports the current draft.

Development

The CI matrix tests PHP 7.4 through 8.5 with current dependencies, tests a Composer-resolvable low dependency set separately, runs PHPStan 2 and PHP CS Fixer, audits production dependencies, and runs the live transport integration test weekly or on demand.

Commits use Conventional Commits. Release Please turns them into a release pull request and applies Semantic Versioning: fix is patch, feat is minor, and feat! or a BREAKING CHANGE footer is major. See RELEASE.md.

Security

See SECURITY.md for private vulnerability reporting.

License

MIT. See LICENSE.MIT.


All versions of guzzle-web-bot-auth-middleware with dependencies

PHP Build Version
Package Version
Requires php Version ^7.4 || ^8.0
guzzlehttp/guzzle Version ^7.0 || ^8.0
ext-sodium Version *
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package olipayne/guzzle-web-bot-auth-middleware contains the following files

Loading the files please wait ...