NovinkaZverejnili sme 50+ Laravel balíkov ako open source
Custom AI apps, agents and automation — Roundly ConsultingRoundly
Všetky balíky
Sentinel for Laravel

Fasáda Sentinel

Všetko ide cez jednu fasádu, RoundlyConsulting\Sentinel\Facades\Sentinel — importujte ju, globálny alias neexistuje. for($model) vráti handle viazaný na jednu pečať, ploché slovesá pracujú s modelom, ktorý im odovzdáte, model($class) pracuje so všetkými riadkami modelu a zvyšok združuje päť pod-prístupov: keys(), ledger(), idempotency(), nonces() a signatures().

use RoundlyConsulting\Sentinel\Enums\Algorithm;
use RoundlyConsulting\Sentinel\Facades\Sentinel;

// One model: a handle bound to a seal (the default one when unnamed)
Sentinel::for($invoice)->verify();
Sentinel::for($invoice, 'identity')->verify();
Sentinel::for($invoice)->by($admin)->because('INC-88: refund fixed by the DBA')->acknowledge();

// Flat verbs act on the model you hand them
Sentinel::seal($invoice, reason: 'Recomputed lines');
Sentinel::verify($invoice, 'financial');
Sentinel::verifyAll($invoice)->allIntact();

// Every row of a model
Sentinel::model(Invoice::class)->scan();

// Sub-accessors
Sentinel::keys()->ring('http')->import('acme-2026-10', Algorithm::Ed25519, $partnerPublicKeyPem, owner: $partner);
Sentinel::ledger()->checkpoint();
Sentinel::idempotency()->run("charge:{$order->id}", scope: 'billing', callback: fn () => $gateway->charge($order));
Sentinel::nonces()->issue('password-reset', ttl: 900, subject: $user);
Sentinel::signatures()->current($request);

Pečate modelov

Názov pečate, ktorú model nedeklaruje, vyhodí SealingMisconfiguredException::unknownSeal (správa vypíše deklarované pečate); null pečať je predvolená pečať modelu.

MetódaVraciaČo robí
for(Model $model, ?string $seal = null)SealHandleHandle viazaný na jednu pečať (pri vynechaní predvolenú).
model(string $class)ModelSealsOperácie nad všetkými riadkami modelu.
sealables()list<class-string<Model>>Najprv sentinel.models, potom každá trieda s riadkami pečatí alebo záznamami v denníku.
check()HealthReportKontrola stavu inštalácie.
seal(Model $model, ?string $seal = null, ?string $reason = null, ?Model $actor = null)SealResultExplicitné zapečatenie; pri zmenenom modeli sa odmietne.
verify(Model $model, ?string $seal = null)VerificationResultOverí jednu pečať.
verifyOrFail(Model $model, ?string $seal = null)VerificationResultOverí, inak vyhodí TamperedModelException.
verifyAll(Model $model)VerificationReportVšetky deklarované pečate jedného modelu.
verifyMany(iterable $models, ?string $seal = null)VerificationReportViac modelov; null pečať = všetky pečate každého z nich.
isIntact(Model $model)boolTrue, ak sú všetky pečate neporušené.
acknowledge(Model $model, string $reason, ?Model $actor = null, ?string $seal = null)AcknowledgementResultPrijme zmenu mimo aplikácie s dôvodom.
unseal(Model $model, string $reason, ?Model $actor = null, ?string $seal = null)boolZámerne odstráni pečať; vráti, či riadok pečate existoval.
ledgerHistory(Model $model, ?string $seal = null, int $limit = 50)list<LedgerRecord>Záznamy denníka, najnovšie prvé (limit 1–1000).
currentSeal(Model $model, ?string $seal = null)?SealRecordUložený riadok pečate, neoverený.
scan(ScanOptions $options)ScanReportOverenie všetkých riadkov po dávkach.
reseal(ResealOptions $options)ResealReportZnovu zapečatí neporušené riadky aktuálnym kľúčom či definíciou.
resealWhere(ResealWhereRequest $request)ResealReportPotvrdí každý vybraný riadok.
updateAndReseal(UpdateAndResealRequest $request)ResealReportOverená hromadná aktualizácia.
sealMissing(BaselineOptions $options)ResealReportBaseline pre riadky, ktoré nikdy nemali pečať.
withoutSealing(Closure $callback, string $reason)mixedSpustí callback s pozastaveným pečatením.
withoutVerification(Closure $callback)mixedSpustí callback s pozastaveným overovaním pri načítaní.
$result  = Sentinel::seal($invoice, reason: 'Recomputed lines');           // SealResult
$result  = Sentinel::verify($invoice);                                       // the default seal
$result  = Sentinel::verifyOrFail($invoice, 'financial');
$report  = Sentinel::verifyAll($invoice);                                    // every seal
$report  = Sentinel::verifyMany(Invoice::query()->latest()->limit(50)->get(), 'financial');
$ok      = Sentinel::isIntact($invoice);
$removed = Sentinel::unseal($invoice, 'GDPR erasure #12', $admin, 'identity');
$history = Sentinel::ledgerHistory($invoice, 'financial', limit: 20);       // list<LedgerRecord>
$stored  = Sentinel::currentSeal($invoice);                                  // ?SealRecord
$classes = Sentinel::sealables();                                            // [Invoice::class, …]

Kľúče

MetódaVraciaČo robí
keys()KeysAccessorKruhy, inventár kľúčov a handly kruhov.
generateKey(GenerateKeyRequest $request)GeneratedKeyVygeneruje kľúč (predvolene do databázy, alebo riadky env).
importKey(ImportKeyRequest $request)KeyInfoImportuje kľúč partnera (alebo vlastný).
rotateKey(RotateKeyRequest $request)RotationResultRotuje podpisový kľúč kruhu.
revokeKey(RevokeKeyRequest $request)KeyInfoOdvolá kľúč v databáze (dôvod je povinný).
retireKey(string $ring, string $keyId)KeyInfoUkončí obdobie overovania kľúča v databáze hneď.
listKeys(?string $ring = null)list<KeyInfo>Null = všetky kruhy; nikdy nie materiál kľúča.
findKey(string $ring, string $keyId)?KeyInfoJeden kľúč v jednom kruhu.
currentKey(?string $ring = null)KeyInfoPodpisový kľúč, inak NoSigningKeyException.
extend(string $driver, Closure $factory)staticZaregistruje driver úložiska kľúčov.

Denník

MetódaVraciaČo robí
ledger()LedgerAccessorKontrolné body, overenie, história, hlava, kotvy.
checkpoint(?CheckpointOptions $options = null)?CheckpointResultJedna dávka; null = nič nečaká.
verifyLedger(?LedgerVerifyOptions $options = null)LedgerReportKontrolné body, kotvy, čakajúce záznamy, hlavy entít.
ledgerHead(?string $connection = null)?CheckpointRecordNajnovší kontrolný bod, neoverený.
anchors()list<string>Názvy nakonfigurovaných kotiev.
extendAnchor(string $driver, Closure $factory)staticZaregistruje driver kotvy.

Idempotencia, nonce a čistenie

MetódaVraciaČo robí
idempotency()IdempotencyAccessorrun() a forget() pre joby, príkazy a webhooky.
runIdempotent(IdempotentCall $call)IdempotentResultSpustí callback najviac raz pre kľúč a scope.
forgetIdempotencyKey(string $key, string $scope)boolČi kľúč existoval.
nonces()NoncesAccessorVydanie, spotrebovanie, jednorazové URL.
issueNonce(IssueNonceRequest $request)IssuedNonceJednorazový token viazaný na účel.
consumeNonce(ConsumeNonceRequest $request)boolTrue práve raz.
signedRoute(SignedRouteRequest $request)stringJednorazová podpísaná URL.
prune(?PruneOptions $options = null)PruneResultZmaže expirované idempotenčné kľúče a nonce.

Podpisy HTTP správ

MetódaVraciaČo robí
signatures()SignaturesAccessorPodpis, overenie, current, owner, contentDigest.
signRequest(RequestInterface $request, string $keyId, ?SigningOptions $options = null)RequestInterfacePodpíše ľubovoľnú PSR-7 požiadavku.
verifyRequestSignature(Request $request, ?string $profile = null)VerifiedSignatureInak HttpSignatureException (401).
verifyResponseSignature(ResponseInterface|ClientResponse $response, ?string $profile = null)VerifiedSignaturePodpísaná odpoveď (PSR-7 alebo Laravel klient).
verifiedSignature(Request $request)?VerifiedSignatureČo sentinel.signed na tejto požiadavke overil.
signatureOwner(Request|VerifiedSignature $from)?ModelVlastník podpisového kľúča.

Handly a pod-prístupy

Všetky sú final readonly objekty, ktoré vracia manažér; každá metóda volá jednu metódu manažéra. Handle kruhu odmietne id kľúča z iného kruhu (UnknownKeyException) a dopyt ModelSeals nad inou triedou modelu sa odmietne (SealingMisconfiguredException::queryModelMismatch). Metódy ModelSeals majú rovnaké predvolené hodnoty ako objekty volieb (chunk 500, checkLedger true, maxFindings 1000); checkSchema a upgradeFormat existujú len v ScanOptions / ResealOptions a v príkazoch.

VstupTriedaMetódy
Sentinel::for($model, ?$seal)SealHandleby(?Model $actor), because(string $reason), name(), definition(), seal(), verify(), verifyOrFail(), isIntact() (this seal only), acknowledge(?string $reason = null), unseal(?string $reason = null), current(), history(int $limit = 50)
Sentinel::model(Invoice::class)ModelSealsdefinition(?string $seal = null), seals(), scan(…), reseal(…), resealWhere(…), updateAndReseal(…), sealMissing(…), find($id), findOrFail($id), unsealedQuery(?string $seal = null)
Sentinel::keys()Accessors\KeysAccessorring(?string $ring = null), all(), rings()
Sentinel::keys()->ring($ring)Accessors\KeyRingHandlename(), current(), find(string $keyId), all(), generate(…), import(…), rotate(?Algorithm $algorithm = null, ?CarbonInterface $activatesAt = null), revoke(string $keyId, string $reason, ?Model $actor = null), retire(string $keyId)
Sentinel::ledger()Accessors\LedgerAccessorcheckpoint(?string $connection = null), verify(?string $connection = null, bool $entities = true, int $chunk = 1000), history(Model $model, ?string $seal = null, int $limit = 50), head(?string $connection = null), anchors()
Sentinel::idempotency()Accessors\IdempotencyAccessorrun(string $key, string $scope, Closure $callback, ?string $fingerprint = null, ?int $ttl = null, ?int $lease = null), forget(string $key, string $scope)
Sentinel::nonces()Accessors\NoncesAccessorissue(string $purpose, ?int $ttl = null, ?Model $subject = null), consume(…), consumeOrFail(…), signedRoute(string $name, array $parameters = [], ?int $ttl = null)
Sentinel::signatures()Accessors\SignaturesAccessorsign(…), verify(Request $request, ?string $profile = null), verifyResponse(…), current(Request $request), owner(Request|VerifiedSignature $from), contentDigest(string $body, DigestAlgorithm $algorithm = DigestAlgorithm::Sha256)

Skratka cez trait modelu

Trait HasSeals, jeho query scopes a makro kolekcie verifySeals() volajú toho istého manažéra — takže ich vidí aj Sentinel::fake():

$invoice->seal('financial');                         // SealResult
$invoice->verifySeal('identity');                    // VerificationResult
$invoice->verifySealOrFail();                        // TamperedModelException when not intact
$invoice->isIntact();                                // every seal
$invoice->acknowledgeTampering('INC-88: refund fixed by the DBA', $admin);

Invoice::query()->whereSealed()->count();
Invoice::query()->whereNotSealed('identity')->get();
Invoice::query()->withSeals()->get()->verifySeals();

Prejavte lásku k open source

Tento balík je zadarmo pod licenciou MIT. Ak vám šetrí čas, jednorazový príspevok alebo členstvo na Patreone nám pomôže ho ďalej udržiavať, testovať a dokumentovať.

Ďalšie spôsoby podpory vrátane kryptomien

Odoslaním daru súhlasíte s našimi podmienkami prijímania darov.

Chcete to zabudovať do svojho produktu?

Naše balíky integrujeme do zákazkových Laravel a AI riešení. Napíšte nám, na čom pracujete, a ozveme sa do 48 hodín.