Download the PHP package zetwypro/zetoken without Composer
On this page you can find all versions of the php package zetwypro/zetoken. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Informations about the package zetoken
Zetoken
Zetoken is a PHP library for generating simple tokens.
โ ๏ธ Security Warning & Usage Limitations
Zetoken is specifically designed to meet the needs of my project. This library was developed to handle WebSocket handshake processes across different programming languages.
Its main purpose is to ensure that tokens can only be generated and decrypted by official applications within my project. Additionally, Zetoken is used to obfuscate identities, such as user IDs or other object IDs, when the data is transmitted through public spaces.
Currently, Zetoken supports integration with Python, Node.js, and PHP.
However, to comply with the global cybersecurity standard "Don't roll your own crypto", I hereby declare that it is:
NOT SUITABLE for:
- Storing highly sensitive data (banking infrastructure, credit cards, medical records)
- Password hashing (primary passwords)
- National-scale critical financial systems
HIGHLY SUITABLE for:
- Quiz or online exam answer tokens
- Ticket tokens or temporary access vouchers
- Obfuscation (securely masking IDs or URL parameters)
- Other non-financial application needs requiring mass token generation
๐ Key Features
-
Encryption
Converts text data into unique numeric tokens -
Decryption
Accurately restores numeric tokens back into the original text data -
Security
Utilizes:keyId(identifier / offset)secretKey(primary key)
Tokens can only be read by parties possessing the same keys.
- Time-Bound Tokens (TTL)
Native support for auto-expiring tokens with built-in NTP Clock Skew tolerance (Leeway).
โ ๏ธ Weaknesses & Limitations
Please note that Zetoken has several technical limitations:
-
Zetoken has not been audited by professional security experts. Therefore, to comply with global security standards, Zetoken is not yet suitable for financial, medical, or critical infrastructure scales.
- The infancy of the algorithm potentially introduces zero-day security vulnerabilities. Therefore, for now, Zetoken should only be used for hashing non-risky or low-risk data.
โ ๏ธ WARNING: ENV CONFIGURATION REQUIRED
This library WILL NOT WORK if you do not define the security keys.
Zetoken does not have fallback keys for security reasons. You MUST include the following configuration in your Environment system / .env file of your project:
If the keys are not found in the ENV or function parameters:
- All encryption processes will fail
- All decryption processes will fail
- The function will immediately return:
false
๐ ๏ธ Generator Tool
Use the following tool to generate our official cryptographic configuration components:
๐งช Stress Test Results (100,000 Iterations)
โ๏ธ System Requirements
Ensure your server or system meets the following modern standards:
- PHP >= 8.2 (Required for
\Random\Randomizerextension support and PCG64 engine). - PHP extension
opensslmust be enabled.
๐ฆ Installation
Use Composer:
๐ป Usage Instructions
1. Standard Usage (Automatically from ENV)
This method is the simplest as it automatically retrieves keys from the .env.
2. Sign & VerifySign Features (3-Layer Security / Manual KeyID)
Use this feature if you want to bind a token exclusively to an entity (e.g., User ID, Transaction Number). Even if the keys are compromised, User A's token cannot be used by User B.
3. Time-Bound Tokens (TTL & Leeway)
You can generate tokens that automatically expire after a certain amount of time (Time-To-Live). Zetoken internally validates the expiration and provides a default leeway of 60 seconds to accommodate minor server clock desynchronization (NTP Clock Skew).
๐ License
MIT License
Created by Anonputraid