Libraries tagged by Enforcement
boundwize/structarmed
1030105 Downloads
Configurable PHP architecture guards — define your layers and rules, then keep them enforced
zidbih/laravel-deadlock
11474 Downloads
Make temporary Laravel workarounds expire and fail CI when ignored.
infocyph/pathwise
29012 Downloads
High-level PHP filesystem workflows powered by Flysystem, including safe I/O, uploads, downloads, archives, directory synchronization, retention, policy enforcement, auditing and storage adapters.
fissible/verdict
5196 Downloads
Policy-bound actions and security evidence for Laravel AI agents.
paragonie/passwdqc
15910 Downloads
Password/passphrase strength checking and enforcement
derhansen/fe_change_pwd
105672 Downloads
Change password for frontend users - Plugin to enable password change for frontend users. Contains configurable password rules and password change enforcement.
dgame/php-ensurance
148248 Downloads
php ensurance
the-firehub-project/phpstan-rules
2401 Downloads
A centralized quality enforcement layer for the FireHub ecosystem, providing shared PHPStan configuration and custom static analysis rules.
silverassist/coding-standards
1959 Downloads
Framework-agnostic PHPCS ruleset (PSR-12 + PHPDoc enforcement) and PHPStan base config shared by all Silver Assist PHP projects, WordPress or not.
padosoft/laravel-ai-finops
4036 Downloads
Enterprise AI spend-governance for Laravel: cross-provider metering, budgets, policy enforcement, chargeback, forecasting, cost-aware routing and FinOps — the governance brick for AI agents. Hooks the official laravel/ai SDK at a single point.
nowo-tech/password-policy-bundle
3170 Downloads
Symfony bundle for password policy enforcements including password history, expiry, and validation
liberusoftware/two-factor-authentication
829 Downloads
TOTP enforcement policy and one-time recovery-code primitives.
konfig/snaptrade-php-sdk
20956 Downloads
Connect brokerage accounts to your app for live positions and trading. ## Rate limiting Two limits apply to requests signed with your `clientId`. The stricter one wins, and exceeding either returns `429 Too Many Requests`. - **Customer-level** — 250 requests/minute by default, scoped to your `clientId` and applied across all endpoints. Reported in `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`. - **Account-level** — 10 requests/minute per account, scoped to (`clientId`, `accountId`). All covered operations for one account draw on the same bucket — reading balances and reading positions share it — and enforcement does not depend on the HTTP method, so updating an account consumes the same bucket as reading it. Only enforced for Personal users, and only for integrations it has been rolled out to — it is not yet in force for every Personal integration. It also does not apply on every operation that documents a 429 below. Where it applies it is reported in `X-RateLimit-Account-Limit`, `X-RateLimit-Account-Remaining` and `X-RateLimit-Account-Reset`. Do not read the absence of those headers as proof the limit is off — some configurations omit the rate limit headers while still enforcing the limit, so header absence tells you nothing about your allowance. On a 429, `X-RateLimit-Remaining: 0` means you hit the customer-level limit and `X-RateLimit-Account-Remaining: 0` means the account-level one. Wait for the corresponding `*-Reset` value (seconds) before retrying, or fall back to exponential backoff with jitter. Not every 429 is explained by those headers. A separate per-authenticated-user limit, reported in no `X-RateLimit-*` header, covers OAuth-authenticated requests and signed requests in configurations where the customer-level limit is not in effect — on the operations that use the default throttles. A few operations override those and are governed by the customer-level limit alone. The two do not stack: a signed request governed by the customer-level limit above is not additionally subject to the per-user one. If a 429 arrives with no header at zero — or with no `X-RateLimit-*` headers at all — honour `Retry-After` and back off. Treat the remaining counts as a hint, not a guarantee that the next request will succeed. Because the customer-level limit applies everywhere, any signed request can return 429. **OAuth-authenticated requests are an exception.** They are not subject to the customer-level limit and do not receive `X-RateLimit-Limit`, `X-RateLimit-Remaining` or `X-RateLimit-Reset` — do not wait on those headers or design around a customer-level allowance on this path. The account-level limit still applies to them on the account-data endpoints above, reported in the `X-RateLimit-Account-*` headers. On operations using the default throttles the per-user limit above applies to them as well, so an OAuth request can be rejected while the account headers still show capacity; on the few operations that override those throttles, OAuth callers have no per-user ceiling at all. Drive retries from `Retry-After` and exponential backoff with jitter rather than from the headers. See https://docs.snaptrade.com/docs/ratelimiting.
happenv-com/laravel-true-modular-phpstan
2260 Downloads
PHPStan extensions for laravel-true-modular: dynamic Eloquent relation resolution and module boundary enforcement.
glueful/tenancy
2614 Downloads
Shared-database, row-level multi-tenancy for Glueful (tenant resolution, scoping, enforcement).