Fasáda Sentinel
Všetko ide cez jednu fasádu, RoundlyConsulting\Sentinel\Facades\Sentinel — importujte ju, globálny alias neexistuje. for($model) vráti handle viazaný na jednu pečať, ploché slovesá pracujú s modelom, ktorý im odovzdáte, model($class) pracuje so všetkými riadkami modelu a zvyšok združuje päť pod-prístupov: keys(), ledger(), idempotency(), nonces() a signatures().
use RoundlyConsulting\Sentinel\Enums\Algorithm;
use RoundlyConsulting\Sentinel\Facades\Sentinel;
// One model: a handle bound to a seal (the default one when unnamed)
Sentinel::for($invoice)->verify();
Sentinel::for($invoice, 'identity')->verify();
Sentinel::for($invoice)->by($admin)->because('INC-88: refund fixed by the DBA')->acknowledge();
// Flat verbs act on the model you hand them
Sentinel::seal($invoice, reason: 'Recomputed lines');
Sentinel::verify($invoice, 'financial');
Sentinel::verifyAll($invoice)->allIntact();
// Every row of a model
Sentinel::model(Invoice::class)->scan();
// Sub-accessors
Sentinel::keys()->ring('http')->import('acme-2026-10', Algorithm::Ed25519, $partnerPublicKeyPem, owner: $partner);
Sentinel::ledger()->checkpoint();
Sentinel::idempotency()->run("charge:{$order->id}", scope: 'billing', callback: fn () => $gateway->charge($order));
Sentinel::nonces()->issue('password-reset', ttl: 900, subject: $user);
Sentinel::signatures()->current($request);Pečate modelov
Názov pečate, ktorú model nedeklaruje, vyhodí SealingMisconfiguredException::unknownSeal (správa vypíše deklarované pečate); null pečať je predvolená pečať modelu.
| Metóda | Vracia | Čo robí |
|---|---|---|
for(Model $model, ?string $seal = null) | SealHandle | Handle viazaný na jednu pečať (pri vynechaní predvolenú). |
model(string $class) | ModelSeals | Operácie nad všetkými riadkami modelu. |
sealables() | list<class-string<Model>> | Najprv sentinel.models, potom každá trieda s riadkami pečatí alebo záznamami v denníku. |
check() | HealthReport | Kontrola stavu inštalácie. |
seal(Model $model, ?string $seal = null, ?string $reason = null, ?Model $actor = null) | SealResult | Explicitné zapečatenie; pri zmenenom modeli sa odmietne. |
verify(Model $model, ?string $seal = null) | VerificationResult | Overí jednu pečať. |
verifyOrFail(Model $model, ?string $seal = null) | VerificationResult | Overí, inak vyhodí TamperedModelException. |
verifyAll(Model $model) | VerificationReport | Všetky deklarované pečate jedného modelu. |
verifyMany(iterable $models, ?string $seal = null) | VerificationReport | Viac modelov; null pečať = všetky pečate každého z nich. |
isIntact(Model $model) | bool | True, ak sú všetky pečate neporušené. |
acknowledge(Model $model, string $reason, ?Model $actor = null, ?string $seal = null) | AcknowledgementResult | Prijme zmenu mimo aplikácie s dôvodom. |
unseal(Model $model, string $reason, ?Model $actor = null, ?string $seal = null) | bool | Zámerne odstráni pečať; vráti, či riadok pečate existoval. |
ledgerHistory(Model $model, ?string $seal = null, int $limit = 50) | list<LedgerRecord> | Záznamy denníka, najnovšie prvé (limit 1–1000). |
currentSeal(Model $model, ?string $seal = null) | ?SealRecord | Uložený riadok pečate, neoverený. |
scan(ScanOptions $options) | ScanReport | Overenie všetkých riadkov po dávkach. |
reseal(ResealOptions $options) | ResealReport | Znovu zapečatí neporušené riadky aktuálnym kľúčom či definíciou. |
resealWhere(ResealWhereRequest $request) | ResealReport | Potvrdí každý vybraný riadok. |
updateAndReseal(UpdateAndResealRequest $request) | ResealReport | Overená hromadná aktualizácia. |
sealMissing(BaselineOptions $options) | ResealReport | Baseline pre riadky, ktoré nikdy nemali pečať. |
withoutSealing(Closure $callback, string $reason) | mixed | Spustí callback s pozastaveným pečatením. |
withoutVerification(Closure $callback) | mixed | Spustí callback s pozastaveným overovaním pri načítaní. |
$result = Sentinel::seal($invoice, reason: 'Recomputed lines'); // SealResult
$result = Sentinel::verify($invoice); // the default seal
$result = Sentinel::verifyOrFail($invoice, 'financial');
$report = Sentinel::verifyAll($invoice); // every seal
$report = Sentinel::verifyMany(Invoice::query()->latest()->limit(50)->get(), 'financial');
$ok = Sentinel::isIntact($invoice);
$removed = Sentinel::unseal($invoice, 'GDPR erasure #12', $admin, 'identity');
$history = Sentinel::ledgerHistory($invoice, 'financial', limit: 20); // list<LedgerRecord>
$stored = Sentinel::currentSeal($invoice); // ?SealRecord
$classes = Sentinel::sealables(); // [Invoice::class, …]Kľúče
| Metóda | Vracia | Čo robí |
|---|---|---|
keys() | KeysAccessor | Kruhy, inventár kľúčov a handly kruhov. |
generateKey(GenerateKeyRequest $request) | GeneratedKey | Vygeneruje kľúč (predvolene do databázy, alebo riadky env). |
importKey(ImportKeyRequest $request) | KeyInfo | Importuje kľúč partnera (alebo vlastný). |
rotateKey(RotateKeyRequest $request) | RotationResult | Rotuje podpisový kľúč kruhu. |
revokeKey(RevokeKeyRequest $request) | KeyInfo | Odvolá kľúč v databáze (dôvod je povinný). |
retireKey(string $ring, string $keyId) | KeyInfo | Ukončí obdobie overovania kľúča v databáze hneď. |
listKeys(?string $ring = null) | list<KeyInfo> | Null = všetky kruhy; nikdy nie materiál kľúča. |
findKey(string $ring, string $keyId) | ?KeyInfo | Jeden kľúč v jednom kruhu. |
currentKey(?string $ring = null) | KeyInfo | Podpisový kľúč, inak NoSigningKeyException. |
extend(string $driver, Closure $factory) | static | Zaregistruje driver úložiska kľúčov. |
Denník
| Metóda | Vracia | Čo robí |
|---|---|---|
ledger() | LedgerAccessor | Kontrolné body, overenie, história, hlava, kotvy. |
checkpoint(?CheckpointOptions $options = null) | ?CheckpointResult | Jedna dávka; null = nič nečaká. |
verifyLedger(?LedgerVerifyOptions $options = null) | LedgerReport | Kontrolné body, kotvy, čakajúce záznamy, hlavy entít. |
ledgerHead(?string $connection = null) | ?CheckpointRecord | Najnovší kontrolný bod, neoverený. |
anchors() | list<string> | Názvy nakonfigurovaných kotiev. |
extendAnchor(string $driver, Closure $factory) | static | Zaregistruje driver kotvy. |
Idempotencia, nonce a čistenie
| Metóda | Vracia | Čo robí |
|---|---|---|
idempotency() | IdempotencyAccessor | run() a forget() pre joby, príkazy a webhooky. |
runIdempotent(IdempotentCall $call) | IdempotentResult | Spustí callback najviac raz pre kľúč a scope. |
forgetIdempotencyKey(string $key, string $scope) | bool | Či kľúč existoval. |
nonces() | NoncesAccessor | Vydanie, spotrebovanie, jednorazové URL. |
issueNonce(IssueNonceRequest $request) | IssuedNonce | Jednorazový token viazaný na účel. |
consumeNonce(ConsumeNonceRequest $request) | bool | True práve raz. |
signedRoute(SignedRouteRequest $request) | string | Jednorazová podpísaná URL. |
prune(?PruneOptions $options = null) | PruneResult | Zmaže expirované idempotenčné kľúče a nonce. |
Podpisy HTTP správ
| Metóda | Vracia | Čo robí |
|---|---|---|
signatures() | SignaturesAccessor | Podpis, overenie, current, owner, contentDigest. |
signRequest(RequestInterface $request, string $keyId, ?SigningOptions $options = null) | RequestInterface | Podpíše ľubovoľnú PSR-7 požiadavku. |
verifyRequestSignature(Request $request, ?string $profile = null) | VerifiedSignature | Inak HttpSignatureException (401). |
verifyResponseSignature(ResponseInterface|ClientResponse $response, ?string $profile = null) | VerifiedSignature | Podpísaná odpoveď (PSR-7 alebo Laravel klient). |
verifiedSignature(Request $request) | ?VerifiedSignature | Čo sentinel.signed na tejto požiadavke overil. |
signatureOwner(Request|VerifiedSignature $from) | ?Model | Vlastník podpisového kľúča. |
Handly a pod-prístupy
Všetky sú final readonly objekty, ktoré vracia manažér; každá metóda volá jednu metódu manažéra. Handle kruhu odmietne id kľúča z iného kruhu (UnknownKeyException) a dopyt ModelSeals nad inou triedou modelu sa odmietne (SealingMisconfiguredException::queryModelMismatch). Metódy ModelSeals majú rovnaké predvolené hodnoty ako objekty volieb (chunk 500, checkLedger true, maxFindings 1000); checkSchema a upgradeFormat existujú len v ScanOptions / ResealOptions a v príkazoch.
| Vstup | Trieda | Metódy |
|---|---|---|
Sentinel::for($model, ?$seal) | SealHandle | by(?Model $actor), because(string $reason), name(), definition(), seal(), verify(), verifyOrFail(), isIntact() (this seal only), acknowledge(?string $reason = null), unseal(?string $reason = null), current(), history(int $limit = 50) |
Sentinel::model(Invoice::class) | ModelSeals | definition(?string $seal = null), seals(), scan(…), reseal(…), resealWhere(…), updateAndReseal(…), sealMissing(…), find($id), findOrFail($id), unsealedQuery(?string $seal = null) |
Sentinel::keys() | Accessors\KeysAccessor | ring(?string $ring = null), all(), rings() |
Sentinel::keys()->ring($ring) | Accessors\KeyRingHandle | name(), current(), find(string $keyId), all(), generate(…), import(…), rotate(?Algorithm $algorithm = null, ?CarbonInterface $activatesAt = null), revoke(string $keyId, string $reason, ?Model $actor = null), retire(string $keyId) |
Sentinel::ledger() | Accessors\LedgerAccessor | checkpoint(?string $connection = null), verify(?string $connection = null, bool $entities = true, int $chunk = 1000), history(Model $model, ?string $seal = null, int $limit = 50), head(?string $connection = null), anchors() |
Sentinel::idempotency() | Accessors\IdempotencyAccessor | run(string $key, string $scope, Closure $callback, ?string $fingerprint = null, ?int $ttl = null, ?int $lease = null), forget(string $key, string $scope) |
Sentinel::nonces() | Accessors\NoncesAccessor | issue(string $purpose, ?int $ttl = null, ?Model $subject = null), consume(…), consumeOrFail(…), signedRoute(string $name, array $parameters = [], ?int $ttl = null) |
Sentinel::signatures() | Accessors\SignaturesAccessor | sign(…), verify(Request $request, ?string $profile = null), verifyResponse(…), current(Request $request), owner(Request|VerifiedSignature $from), contentDigest(string $body, DigestAlgorithm $algorithm = DigestAlgorithm::Sha256) |
Skratka cez trait modelu
Trait HasSeals, jeho query scopes a makro kolekcie verifySeals() volajú toho istého manažéra — takže ich vidí aj Sentinel::fake():
$invoice->seal('financial'); // SealResult
$invoice->verifySeal('identity'); // VerificationResult
$invoice->verifySealOrFail(); // TamperedModelException when not intact
$invoice->isIntact(); // every seal
$invoice->acknowledgeTampering('INC-88: refund fixed by the DBA', $admin);
Invoice::query()->whereSealed()->count();
Invoice::query()->whereNotSealed('identity')->get();
Invoice::query()->withSeals()->get()->verifySeals();Prejavte lásku k open source
Tento balík je zadarmo pod licenciou MIT. Ak vám šetrí čas, jednorazový príspevok alebo členstvo na Patreone nám pomôže ho ďalej udržiavať, testovať a dokumentovať.
Ďalšie spôsoby podpory vrátane kryptomienOdoslaním daru súhlasíte s našimi podmienkami prijímania darov.
Chcete to zabudovať do svojho produktu?
Naše balíky integrujeme do zákazkových Laravel a AI riešení. Napíšte nám, na čom pracujete, a ozveme sa do 48 hodín.