Download the PHP package oxid-esales/security-module without Composer

On this page you can find all versions of the php package oxid-esales/security-module. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package security-module

OXID Security Module

A collection of security features for OXID eShop

Development Latest Version PHP Version

Quality Gate Status Coverage Technical Debt

Compatibility

This module assumes you have OXID eShop Compilation version 7.5.0 installed.

Branches

Development installation

To be able running the tests and other preconfigured quality tools, please install the module as a root package.

The next section shows how to install the module as a root package by using the OXID eShop SDK.

In case of different environment usage, please adjust by your own needs.

Development installation on OXID eShop SDK

The installation instructions below are shown for the current SDK for shop 7.5. Make sure your system meets the requirements of the SDK.

  1. Ensure all docker containers are down to avoid port conflicts

  2. Clone the SDK for the new project

  3. Clone the repository to the source directory

  4. Run the recipe to setup the development environment

You should be able to access the shop with http://localhost.local and the admin panel with http://localhost.local/admin (credentials: [email protected] / admin)

Building the documentation locally

If the "Development installation on OXID eShop SDK" section was followed, the documentation repository will be already cloned and prepared to use for you, so the documentation can be built locally:

Features

Password Strength Policy

This module provides password strength estimation for any string input. It can validate password length and character variety based on configurable settings. It also includes a visual password strength indicator with a progress bar for real-time feedback via an Ajax widget.

Configuration

Captcha Protection

The module features Image Captcha protection to prevent automated bot submissions. Users must enter the text displayed in the captcha image, with an audio captcha option available for accessibility. A honeypot captcha is also implemented as a hidden field to detect and block bots without affecting the user experience.

Configuration

Two-Factor Authentication (2FA)

The module provides Two-Factor Authentication using email-based One-Time Password (OTP) verification. When enabled, users are required to enter a verification code sent to their email address after logging in with their credentials.

Configuration

OTP email template (CMS content)

The OTP email is rendered from a CMS content block (OXLOADID: oesm2faotpemail, folder CMSFOLDER_EMAILS) so operators can edit the subject and body in the admin. The {{ otp }} and {{ minutes }} placeholders are substituted at send time — {{ minutes }} is the configured OTP code lifetime (oeSecurityTwoFactorAuthOtpCodeLifetime). If the CMS content is missing or inactive, the module falls back to the built-in translated plain-text mail.

Note: the content is seeded by migration for shop 1 in German and English only. Depending on your shop setup (CE / PE / EE) and the active languages, it may be necessary to add the mail template into CMS content manually — e.g. for additional languages or for EE subshops other than shop 1.

Running the tests and quality tools

Check the "scripts" section in the composer.json file for the available commands. Those commands can be executed by connecting to the php container and running the command from there, example:

Commands can be also triggered directly on the container with docker compose, example:

Testing

Linting, syntax check, static analysis

Check the "scripts" section in the composer.json file for the available commands. Those commands can be executed by connecting to the php container and running the command from there, example:

Unit/Integration/Acceptance tests


All versions of security-module with dependencies

PHP Build Version
Package Version
Requires php Version ^8.3
oxid-esales/graphql-base Version ^13.1
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package oxid-esales/security-module contains the following files

Loading the files please wait ...