Download the PHP package straschek-io/typo3-tor-blocker without Composer

On this page you can find all versions of the php package straschek-io/typo3-tor-blocker. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package typo3-tor-blocker

TYPO3 Tor Blocker

This extension answers every frontend request coming from a Tor exit node with 403 Forbidden and a short notice page.

Form spam bots like to hide behind the Tor network: every submission arrives from a different exit node, so blocking single IP addresses is pointless. The Tor Project publishes the complete list of exit nodes, which makes blocking all of them straightforward. Legitimate visitors via Tor are rare on most websites; if they matter for yours, this extension is not for you.

How to install

Composer mode:

Classic mode: copy the extension to typo3conf/ext/tor_blocker/, activate it in the extension manager and dump the autoload information.

How to use

  1. Download the list once, as the user the web server runs as (see Permissions):

  2. Keep it up to date, hourly. Either add a scheduler task "Execute console commands" with torblocker:update, or skip the scheduler and use a cron job running as the web server user:

    In classic mode the binary is typo3/sysext/core/bin/typo3.

  3. Keep an eye on it: the reports module (system extension reports) shows the number of stored addresses and the age of the list under "Tor Blocker". It warns when no list is stored or the list is older than 24 hours, and reports an error when the stored list cannot be loaded.

  4. Check that it works: request the site from a listed address (Tor Browser, or curl from a listed exit node) and expect a 403 with Cache-Control: no-store.

That's it. The middleware runs first in the frontend stack, before static file caches and before the page is resolved. The backend is never blocked.

Configuration

Extension configuration, all optional:

Setting Default
listUrl https://check.torproject.org/torbulkexitlist Plain text, one IP address per line
minimumEntries 500 A download with fewer valid addresses is rejected and the stored list is kept
templatePath EXT:tor_blocker/Resources/Private/Templates/Blocked.html Fluid template of the notice page, gets {htmlLanguage} and {labels.title}, {labels.message}

The notice page is available in English and German, chosen by the browser's Accept-Language header (best quality first), since the site and its languages are not resolved yet at that point.

Good to know

Permissions

torblocker:update runs on the command line, the list is read by the web server process. The directory and the file get the permissions configured in $GLOBALS['TYPO3_CONF_VARS']['SYS'] (folderCreateMask, fileCreateMask, createGroup; defaults 2775, 0664, none), independent of the umask of the CLI user. Run the command and the scheduler as the web server user anyway, or make sure that user can read <var path>/tor_blocker/exit-nodes.php; the command fails with exit code 1 if the file is not readable after writing.

Opcache

The web server's opcache notices the new list by its modification time, within opcache.revalidate_freq seconds (default 2). With opcache.validate_timestamps = 0 the web server keeps the old list, and also keeps blocking after the file was deleted, until PHP-FPM is reloaded. Add the reload to your update routine in that case.

Development

Bootstraps a full TYPO3 14.3 dev instance (DDEV required, PHP 8.4) with a seeded page and a dev list that blocks the loopback addresses only, so requests from inside the web container get the notice page while your browser gets the page. Frontend: https://typo3-tor-blocker.ddev.site/ — Backend: /typo3 (admin / TorBlocker14!) Run tests with ddev composer test, code style with ddev composer cs.

The lowest supported combination, TYPO3 10.4 on PHP 7.4, runs in Docker:

Activate the pre-commit hook once per clone: git config core.hooksPath .githooks

Compatibility

Compatible with TYPO3 10.4, 12.4, 13.4 and 14.3, PHP 7.4 – 8.5. TYPO3 11.5 is not tested. Covered by PHPUnit tests against TYPO3 10.4 (PHP 7.4), 12.4 (PHP 8.2), 13.4 (PHP 8.3) and 14.3 (PHP 8.3 – 8.5). From TYPO3 13 on the notice page is rendered through the ViewFactoryInterface, on 10 and 12 through StandaloneView.

Works for me, may work for you.


All versions of typo3-tor-blocker with dependencies

PHP Build Version
Package Version
Requires php Version ^7.4 || ^8.0
typo3/cms-core Version ^10.4 || ^12.4 || ^13.4 || ^14.3
typo3/cms-fluid Version ^10.4 || ^12.4 || ^13.4 || ^14.3
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package straschek-io/typo3-tor-blocker contains the following files

Loading the files please wait ...