Download the PHP package ssbityukov/filament-command-center without Composer

On this page you can find all versions of the php package ssbityukov/filament-command-center. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package filament-command-center

Filament Command Center

Run pre-approved Artisan and shell commands from your Filament panel.

Every command is an entry in an allow-list. There is no free-form command input anywhere, user input never becomes a structural part of a command line, and each command can require its own gate.

Status

Stable. 442 tests run against PHP 8.3, 8.4 and 8.5 × Laravel 12 and 13 in CI, with PHPStan level 6, Pint, and two guard scripts that assert no shell execution primitive exists in src/ and that the core carries no Filament import.

There is no browser suite. Everything behind the login — pages, actions, authorization, queued runs, live output, the editor — is covered by Livewire component tests, which is the same bar the package this one is a port of sets.

Credits

This package is a Filament port of farsidev/nova-command-center, which worked out what a command runner in an admin panel should feel like. The catalogue, the run modal, the live output and the history all follow the shape it established; the argv model, the source layer and the checks are this package's own. Thanks to its authors.

Requirements

PHP 8.3+, Laravel 12 or 13, Filament 5.

The suite runs against each of those combinations in CI. Older versions are not listed because they are not tested, not because they are known to break.

Linux and macOS. Windows is untested and not claimed. The reason is not effort but behaviour: on Unix an argument array goes to proc_open and execs the binary with no shell involved, while on Windows Symfony always converts it to an escaped command string. That is a different guarantee, and this package has never run a test against it.

Installation

Register the plugin on your panel:

Publish the config:

Say who may reach the module. Until you do, nobody sees it — the gate is undefined, and Laravel denies an undefined gate:

Swap is_admin for whatever your application uses — a role check, a policy call, an email allow-list. The three abilities are named in config/command-center.php under abilities, so you can rename them.

access decides whether the catalogue, a run and the history appear at all. manage-commands guards the database editor, and prune-history guards deleting run records. Setting abilities.access to null shows the module to everyone who can open the panel; that is a decision worth making on purpose, because each command's own ability is then the only thing left.

php artisan command-center:check warns when the access gate is missing, so a module that has gone quiet reports why instead of looking broken.

Everything publishable, if you need the rest:

Tag What it gives you
command-center-config config/command-center.php — where commands are defined
command-center-migrations The runs and commands tables, for the database history driver and the database source
command-center-views The Blade views, if you want to change the markup

Migrations are published rather than run automatically: an app using the cache history driver needs no tables, and a package that creates them on install has outstayed its welcome. Publishing an existing file is skipped rather than overwritten — pass --force if you mean to replace it.

What you get out of the box

The published config ships a starter set, so the catalogue is not empty on the first visit: cache and optimisation clears, cache:forget, queue restart, failed job listing and retry, migrate:status, storage:link, about, plus three that change the running application — migrate, down and up. The last three ask for confirmation before they run.

It is still an allow-list. Delete what you do not want, and give anything you consider dangerous its own ability:

Nothing outside that array can be executed, whatever a request asks for.

Variables and flags

A run template holds tokens. Each token is filled from a variable and becomes one argv element — never part of a command string:

Variable types: text, select (with options), boolean, model (with model, title_attribute, value_attribute). A blank optional variable removes its whole argv element, so --path={path} disappears rather than becoming --path=.

'redact' => true keeps a value out of run history while still passing it to the process.

Authorization

Commands you cannot run are absent from the catalogue payload entirely, and the run action re-checks the gate server-side. Reading a run's output requires the same ability as running the command that produced it.

Three package-level abilities, all configurable under abilities:

Ability Guards
command-center:access Seeing the module at all: catalogue, run view, history
command-center:prune-history Deleting run records, individually or in bulk
command-center:manage-commands The database command editor

All three deny until your application defines them. If a panel needs its own rule instead, CommandCenterPlugin::make()->authorize(fn ($user) => …) overrides access for that panel.

Queued runs reload the actor through the panel's auth guard (or command-center.auth_guard). Without that, a worker using the default guard looks up the wrong user model.

Queued commands

The run view streams output while the job runs, shows progress, and offers Cancel. Emit progress from your own command with the documented sentinel:

Nothing is inferred from log volume: a command that reports nothing shows an indeterminate bar.

Run history

The default cache driver needs no migration. For a durable audit trail:

Commands in the database

Opt in by adding the source:

The table it reads comes from the published migrations, so publish and run them first — the editor has nowhere to write otherwise:

This enables a structured editor in the panel, guarded by command-center:manage-commands. command-center:check fails if the source is enabled while that gate is undefined.

Validating in CI

Exits non-zero on unknown tokens, variables with no token, shell commands while shell mode is off, undefined abilities, invalid timeouts, and an unguarded database editor.

Security posture

  1. Allow-list only. A command absent from every source cannot be run by any request. The HTTP payload carries a command key, never a command string.
  2. The package never builds a command string. Execution always uses Process with an argument array; Process::fromShellCommandline() appears nowhere in src/, enforced by a CI script. A value containing ; rm -rf / stays one argv element.
  3. Shell mode is off by default. Enabling it never unlocks arbitrary commands — shell definitions remain allow-listed and are executed as argv vectors.
  4. Authorization is enforced server-side in the run action, in the dispatcher, and again inside the queued job, because a gate can be revoked between dispatch and execution.
  5. Input is validated before substitution. A model variable re-resolves the submitted id through its own scoped query, so a scoped select cannot reach another tenant's record.
  6. A token cannot become an option or the binary. A value opening an argv element may not start with - unless the variable opts in, and a token may not sit in the command position at all.

Limitations

Read these before adopting. They are properties of the design, not bugs.

Deep dives

Guide What it covers
Configuration Every config key, and what breaks if it is wrong
Command sources Config, database and custom sources
Security model The threat model and every control
Authorization Gates, abilities and who may read a run
Queued execution and progress Queueing, live output, progress, cancel

Testing

License

MIT. See LICENSE.


All versions of filament-command-center with dependencies

PHP Build Version
Package Version
Requires php Version ^8.3
filament/filament Version ^5.0
illuminate/console Version ^12.0|^13.0
illuminate/contracts Version ^12.0|^13.0
illuminate/database Version ^12.0|^13.0
illuminate/support Version ^12.0|^13.0
spatie/laravel-package-tools Version ^1.92
symfony/process Version ^7.0|^8.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package ssbityukov/filament-command-center contains the following files

Loading the files please wait ...