Download the PHP package wobqqq/nova-aegis-input-sanitizer without Composer

On this page you can find all versions of the php package wobqqq/nova-aegis-input-sanitizer. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package nova-aegis-input-sanitizer

Aegis Input Sanitizer

CI Packagist PHP PHPStan License: MIT

Input Sanitizer is a module of Aegis, the security suite for Laravel Nova. It refuses a request whose query string, body, headers or URL carry an XSS, template injection, command injection or path traversal payload before it reaches your application, and is configured from the Aegis → Settings page.

🚀 Features

📦 Requirements

📥 Installation

1. Install the package

The service provider is discovered automatically.

2. Run the migrations

This creates the Aegis settings table if the core is new to the application; the module adds no table of its own.

3. Set up Aegis (once per application)

If Aegis is new to the application, register its tool and define the viewAegis gate as the Aegis README describes. Skip this step if you already use another Aegis module.

4. Turn it on in Nova

Open Aegis → Settings → Input Sanitizer in Nova, review the patterns and the excluded inputs, switch Scan the requests on and save. Nothing is blocked until you do.

5. Customise the blocked-request page (optional)

Publish the built-in page, or name any view of your own in the settings:

⚙️ Configuration

Everything is set in the Input Sanitizer section of the Aegis settings:

Setting Default
Scan the requests off Nothing is scanned until it is on.
Block at score 1 Refuse a request once this many pattern matches are found in it (1 to 1000).
Page shown to a blocked request aegis-input-sanitizer::blocked A Blade view name; it must exist when saved, and the built-in page is used if it is gone later.
Scan JSON request bodies off Off, JSON bodies pass unscanned (their query string, headers and URL are still scanned).
Scan Nova requests too off Nova's routes (nova.path, nova-api, nova-vendor). The Aegis settings API is never scanned.
Log blocked requests on A warning in the default log channel, without values.
Patterns one per kind A PCRE pattern with its delimiters (~<script~i), up to 1000 characters; leave one empty to turn that kind off.
Inputs never scanned none Input names or dotted paths, case-insensitive, up to 150.
Headers never scanned none Header names, case-insensitive, up to 150. Cookie and Accept always.

The settings are cached in the store named by the core's aegis.cache_store (AEGIS_CACHE_STORE), the default store otherwise.

🆘 Recovery commands

If a pattern that is too broad blocks your site or your API, turn the module off from the console. The other settings are kept:

The Aegis page in Nova stays reachable while the module is on (unless you enabled Scan Nova requests too and a pattern blocks Nova itself), so you can also fix the pattern there. php artisan aegis:check reports a saved pattern that is skipped.

⚠️ Good to know

⬆️ Upgrading

See CHANGELOG.md.

🔒 Security

Please report a vulnerability privately, as described in SECURITY.md.

🛠️ Development

The toolchain runs in Docker, the host needs nothing but docker and make. The module is developed against the core's checkout in the sibling directory ../nova-aegis (a Composer path repository; the container mounts the parent directory). No Nova license is needed: development and CI run on a test double of Nova in stubs/nova (installed as laravel/nova from a path repository, never shipped). Applications still install the real Nova.

make test.nova copies the repository to a temporary directory, installs the real laravel/nova from nova.laravel.com there and runs Pest; it needs your own Nova license in auth.json (gitignored), and NOVA_VERSION=5.9.3 make test.nova picks a release your license may download. The working copy, its vendor/ and composer.lock are left untouched.


All versions of nova-aegis-input-sanitizer with dependencies

PHP Build Version
Package Version
Requires php Version ^8.4
laravel/framework Version ^12.0 || ^13.0
laravel/nova Version ^5.0
wobqqq/nova-aegis Version ^1.1 || ^2.0 || dev-main
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package wobqqq/nova-aegis-input-sanitizer contains the following files

Loading the files please wait ...