Download the PHP package tuhin-su/livewire-swal without Composer

On this page you can find all versions of the php package tuhin-su/livewire-swal. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package livewire-swal

Laravel & Livewire 3+ SweetAlert2 Helpers

Latest Version on Packagist Total Downloads License

A simple, reusable global SweetAlert2 integration for Laravel and Livewire 3 with clean, secure, one-line PHP wrappers.


Features


Requirements


Installation & Setup

Choose between the two installation methods depending on your project architecture:

Option A: Zero-Configuration (Recommended & Default)

Use this option if you want the package to work instantly without running build tools, installing NPM packages, or modifying layout files.

  1. Install via Composer:

    That's it! The package automatically injects the SweetAlert2 CDN and the event wrapper into the closing </body> tag of all HTML pages.

    [!TIP] Self-Hosting / Customizing SWAL CDN: By default, SweetAlert2 is loaded via jsDelivr CDN. If you want to host it yourself locally or use a custom CDN URL, publish the config file using php artisan vendor:publish --tag=laravel-swal-config and edit the swal_cdn key in config/laravel-swal.php. Set it to false or null if you already load SweetAlert2 separately in your layouts.

  2. Use the Trait in your Livewire Component:

Option B: Manual Asset Compilation (NPM + Vite)

Use this option if you prefer to compile the assets locally, bundle SweetAlert2 inside your custom built assets, avoid CDNs, or customize the frontend JavaScript logic.

  1. Install via Composer:

  2. Publish Configuration & Assets: Run the publish command to copy files into your application's resources directory:

    This will create:

    • Config file at config/laravel-swal.php
    • JS wrapper file at resources/js/vendor/laravel-swal/swal.js
  3. Disable Auto-Injection: Open config/laravel-swal.php and set auto_inject to false to disable the middleware CDN injection:

  4. Install SweetAlert2 via NPM:

  5. Register Wrapper in JavaScript: Import SweetAlert2 and register the helper script in your resources/js/app.js (or Vite entrypoint):

    Make sure your layout contains your Vite directive: @vite(['resources/css/app.css', 'resources/js/app.js']).

  6. Use the Trait in your Livewire Component:

Helper Methods

1. Toasts (Small, Top-End)

Example

You can pass extra SweetAlert2 options to override defaults:


2. Modals (Larger Dialogs)

Example


3. Confirm Modal

Triggers a confirmation prompt and dispatches a Livewire event upon acceptance.

Example

Listen for it in your component using the #[On] attribute:


4. Generic Input Prompts

Prompt the user for a value and return it to a Livewire event listener.

Example

In your listener, access the value via $payload['value']:


5. Password Prompt Preset

A wrapper around swalTakeInput preset for secure password fields.

Example


6. Verify Current User Password Flow

Prompts for the password, verifies it against the authenticated user's current password (using Hash::check), shows an automated feedback toast, and dispatches true/false events.


Secure Actions (Bypass Prevention & Multi-Step Verification)

Standard event-driven flows (like swalConfirm) are dispatched to the frontend and rely on the client to send a follow-up event back to the server to trigger the final action. A malicious user can open the browser console and manually dispatch the target event (e.g. Livewire.dispatch('users.delete', { id: 5 })), completely bypassing any frontend SweetAlert confirmation.

To solve this, the library provides a secure cryptographically signed action system:

  1. Server-side Signature: The server-side trait encrypts the target method name and its parameters into a secure payload signed using your application key (APP_KEY). This payload includes safety constraints like expiration timestamp, user session ID, and component class validation.
  2. Multi-Step Client Prompts: The client receives this encrypted payload and sequentially prompts the user (e.g. first confirmation, then password verification) depending on your options.
  3. Internal Server-side Execution: When confirmed, the client dispatches the encrypted payload back to the server. The server decrypts it, validates all constraints (e.g. session matching and time validity), checks the password, and calls the target method directly on the component instance.

Important Security Rule: Define your target execution methods as protected or private (e.g., protected function deleteUser($id)). Since Livewire only exposes public methods to the frontend, clients cannot invoke the method directly under any circumstances. The only entry point is the secure decryption handler in the trait.

Usage

Call $this->swalSecureAction from your component:

Direct JS Invocation (Triggering from Frontend)

Sometimes you may want to trigger a secure verification directly from custom Javascript, Alpine.js, or an inline onclick handler in your Blade template, rather than dispatching it from a Livewire PHP method call.

You can achieve this in two steps:

  1. Generate the Encrypted Token: Call swalGenerateSecureActionPayload() on the server side (e.g. inside render() or mount, and pass it to your view).
  2. Execute in JavaScript: Call window.swalExecuteSecureAction(payload, requirePassword, options) directly in your template.

Example

In your Livewire Component (PHP):

In your Blade Template (HTML/JS):

Full Multi-Step Example

First, trigger the secure action flow when a user clicks a button:


JavaScript-only Usage

All SweetAlert2 helpers are bound to the global window object and can be called directly in your custom frontend JavaScript (e.g. within Blade script tags, Alpine.js handlers, or custom assets):

1. Trigger Toasts (Small, Top-End)

2. Trigger Modals (Larger Center Dialogs)

3. Ask for Confirmation (Returns Promise)

Returns a promise that resolves to true (if confirmed) or false (if cancelled):

4. Prompt for Text Input (Returns Promise)

Returns a promise that resolves to the entered string, or null if the user cancelled the dialog:

5. Prompt for Password (Returns Promise)

Returns a promise that resolves to the entered password string, or null if cancelled:


Component-Targeted Events (thenEventTo)

Use thenEventTo to target specific Livewire components by their component name instead of broadcasting the event globally:


Security Notes

  1. Password Prompts: Plaintext passwords are sent back to the Livewire component for verification via Livewire event payloads. Always ensure your application is running over HTTPS to secure this transmission, and prevent logging of sensitive request/event bodies.
  2. Centralization: Keep SweetAlert2 logic centralized to prevent inline JS script execution issues and maintain a strong Content Security Policy (CSP).

All versions of livewire-swal with dependencies

PHP Build Version
Package Version
Requires php Version ^8.1
illuminate/support Version ^10.0|^11.0|^12.0|^13.0
livewire/livewire Version ^3.0|^4.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package tuhin-su/livewire-swal contains the following files

Loading the files please wait ...