Download the PHP package org_heigl/password-middleware without Composer

On this page you can find all versions of the php package org_heigl/password-middleware. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package password-middleware

Password-Middleware

Whenever you are handling passwords you should as soon as possible convert the plaintext that is sent over-the-wire into something that can not leak the cleartext-password.

For that purpose I built a Password-ValueObject that can replace the password and allows you to safely handle it fore whatever need you have.

What is missing in the ValueObject though is the possibility to actually get the password from the request and convert it directly. This is what this middleware does. It intercepts the request, converts every parameter that is configured into a password-ValueObject and replaces the plaintext password in the request.

This will only work for form-parameters that were sent via POST request. You should never ever send passwords or other sensitive information via GET parameters as they will be recorded in the servers access logs!!!

Installation

Do I really need to describe this?

Usage

Now you can use this in your controller:

Caveat: Currently only fields in the first level of the parsed body are available! So if you nest parameters this will currently not work! This is one of the next features that will be implemented!

Caveat: Currently the raw body will not be modified! So the clear text password will always be in the raw request stream! This is also one of the next things on the list!


All versions of password-middleware with dependencies

PHP Build Version
Package Version
Requires php Version ^7.3|^8.0
psr/http-message Version ^1.0
psr/http-server-middleware Version ^1.0
org_heigl/password Version ^1.0.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package org_heigl/password-middleware contains the following files

Loading the files please wait ....