Download the PHP package phattarachai/laravel-cloudflare without Composer
On this page you can find all versions of the php package phattarachai/laravel-cloudflare. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download phattarachai/laravel-cloudflare
More information about phattarachai/laravel-cloudflare
Files in phattarachai/laravel-cloudflare
Package laravel-cloudflare
Short Description Purge the Cloudflare edge cache, toggle development mode, register tunnel DNS records, and sync WAF custom rules from artisan — built for apps behind a shared Cloudflare zone.
License MIT
Informations about the package laravel-cloudflare
Laravel Cloudflare
Purge the Cloudflare edge cache, toggle Development Mode, and register tunnel DNS records from
artisan. Built for a fleet of apps sharing one Cloudflare zone behind a cloudflared tunnel, where
purge_everything and Enterprise-only hosts/prefixes purges are both wrong.
Install
Set the zone id (a public identifier, safe to commit) and, if you register DNS, the tunnel id:
The API token is resolved at runtime and falls back to the process env, so on a self-hosted runner
you inject CLOUDFLARE_API_TOKEN once (in the runner's .env) and no repo needs a secret. A
Zone → Cache Purge scope covers purge and dev-mode; add Zone → DNS Edit to use cloudflare:dns,
and Zone → Zone WAF Edit to use cloudflare:waf.
Purge
Purges by exact files derived from public/build/manifest.json. Make it the last deploy step:
When there is no token or no manifest it exits 0 without calling the API, so dev, tests, and a not-yet-configured repo keep CI green.
Development Mode
DNS
Upsert-only — it never deletes a record it did not declare, so it is safe against the shared zone.
Declare an app's own records in config/cloudflare.php and a bare php artisan cloudflare:dns
upserts them — handy as a one-off when spinning up a new subdomain:
WAF custom rules
Upsert-only, keyed by a tag embedded in each rule's description — it never touches a rule it did
not declare, so it is safe against the shared zone. The canonical use is a Managed Challenge on
/admin: bots and brute-force hit the edge challenge, real browsers pass near-invisibly, and the
API is left alone (a challenge needs a browser + cf_clearance cookie, so it would break XHR,
mobile, and webhooks). Needs a Zone → Zone WAF Edit token.
Declare the rules in config/cloudflare.php. Each carries a unique tag, an action (default
managed_challenge), and EITHER declarative paths (the command builds the expression and, absent
hosts, scopes it to this app's own host) OR a raw expression for full control:
Verify: a challenged request returns 403 with a cf-mitigated: challenge header (curl always lands
here — it can't solve the JS challenge); a passed request has no cf-mitigated header and holds a
cf_clearance cookie (HttpOnly — visible in DevTools → Application → Cookies).
Testing
All versions of laravel-cloudflare with dependencies
spatie/laravel-package-tools Version ^1.16
illuminate/console Version ^11.0|^12.0|^13.0
illuminate/http Version ^11.0|^12.0|^13.0
illuminate/support Version ^11.0|^12.0|^13.0