PHP code example of rennf93 / guard-core-php

1. Go to this page and download the library: Download rennf93/guard-core-php library. Choose the download type require.

2. Extract the ZIP file and open the index.php.

3. Add this code to the index.php.
    
        
<?php
require_once('vendor/autoload.php');

/* Start to develop here. Best regards https://php-download.com/ */

    

rennf93 / guard-core-php example snippets


use RenzoFranceschini\GuardCore\Config\SecurityConfig;
use RenzoFranceschini\GuardCore\Engine\GuardEngine;

$config = new SecurityConfig(
    enableRedis: false,
    blacklist: ['192.0.2.0/24'],
    rateLimit: 100,
    rateLimitWindow: 60,
    enableRateLimiting: true,
);

$engine = new GuardEngine($config);

$config = new SecurityConfig(
    enableRedis: false,
    exemptIps: ['198.51.100.7', '198.51.100.0/28'],
);

$engine = new GuardEngine($config);

$engine = new GuardEngine($config);
$engine->rateLimitHandler()->setGeoResolver(
    static fn (string $ip): string => $ipinfo->countryOf($ip) // your geo lookup
);

$request->state()->routeConfig = new RouteConfig(
    geoRateLimits: ['DE' => ['limit' => 5, 'window' => 60], '*' => ['limit' => 20, 'window' => 60]],
);

use RenzoFranceschini\GuardCore\GeoIp\CountryResolver;

final class MyGeoIp implements CountryResolver
{
    public function getCountry(string $ip): ?string
    {
        return $this->mmdb->countryOf($ip); // your lookup, null when unresolved
    }
}

$config = new SecurityConfig(
    enableRedis: false,
    blockedCountries: ['CN', 'RU'],
    geoIpDbPath: __DIR__ . '/country_asn.mmdb', // or geoIpHandler: new MyGeoIp(),
);

$config = new SecurityConfig(
    enableRedis: false,
    enableCors: true,
    corsAllowOrigins: ['https://app.example.com'],
    corsAllowMethods: ['GET', 'POST'],
);
$engine = new GuardEngine($config);

foreach ($engine->corsResponseHeaders($request) as $name => $value) {
    $response = $response->withHeader($name, $value);
}

$config = new SecurityConfig(
    enableRedis: false,
    securityHeaders: [
        'enabled' => true,
        'hsts' => ['max_age' => 31536000, 'olicy' => 'geolocation=(self)', // '' removes the header
        'custom' => ['X-Request-Id' => 'trace'],      // lands last, may override anything
    ],
);
$engine = new GuardEngine($config);
foreach ($engine->responseHeaders() as $name => $value) {
    $response = $response->withHeader($name, $value);
}

$config = new SecurityConfig(
    enableRedis: false,
    behaviorScanResponseBody: true,
    globalBehaviorRules: [
        ['rule_type' => 'return_pattern', 'threshold' => 5, 'window' => 60,
         'pattern' => 'status:404', 'action' => 'ban', 'ban_duration' => 600],
    ],
);
$engine = new GuardEngine($config);

// Route-level rules (usage rules run automatically on allowed requests):
$engine->execute($request); // tracks routeConfig->behaviorRules usage/frequency

// Response side: adapters call this on every pass-through response:
$engine->processResponse($request, $response);

$route = new RouteConfig(
    enableSuspiciousDetection: true,          // route-level kill switch / opt-in
    excludedDetectionParams: ['search_hint'], // replaces the global param set
    enabledDetectionCategories: ['sqli'],     // narrows the category set
    detectionScanBody: false,                 // skips the body surface only
);
$request->state()->routeConfig = $route;