• Stars
    star
    172
  • Rank 221,201 (Top 5 %)
  • Language
    PHP
  • License
    MIT License
  • Created over 11 years ago
  • Updated 8 months ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

An input protector for Laravel

Laravel Binput

Laravel Binput was created by, and is maintained by Graham Campbell, and is an input protector for Laravel that prevents potentially dangerous elements like <script> tags in any input you receive, from doing harm. It utilises my Laravel Security package, which cleans the input using voku/anti-xss. Feel free to check out the change log, releases, security policy, license, code of conduct, and contribution guidelines.

Banner

Build Status StyleCI Status Software License Packagist Downloads Latest Version

Installation

This version requires PHP 8.0-8.2 and supports Laravel 9-10.

Binput L5.5 L5.6 L5.7 L5.8 L6 L7 L8 L9 L10
5.1
6.2
7.1
8.0
9.1
10.0
11.0

To get the latest version, simply require the project using Composer:

$ composer require "graham-campbell/binput:^11.0"

Once installed, if you are not using automatic package discovery, then you need to register the GrahamCampbell\Security\SecurityServiceProvider and GrahamCampbell\Binput\BinputServiceProvider service providers in your config/app.php.

You can also optionally alias our facade:

        'Binput' => GrahamCampbell\Binput\Facades\Binput::class,

Configuration

Laravel Binput requires no configuration. Just follow the simple install instructions and go!

Usage

Binput

This is the class of most interest. It is bound to the ioc container as 'binput' and can be accessed using the Facades\Binput facade. There are a few public methods of interest.

The 'all', 'get', 'input', 'only', 'except', and 'old' methods have an identical api to the methods found on the laravel request class accept from they all accept two extra parameters at the end. The first extra parameter is a boolean representing if the input should be trimmed. The second extra parameter is a boolean representing if the input should be xss cleaned. Both extra parameters are default to true.

There are two additional methods added to the public api. The first is a method called 'map' which will remap the output from the 'only' method. The 'map' function requires an associative array as the first parameter. The second method is the 'clean' function. It takes three parameters. The first is the value to be cleaned (it can be an array, and will be recursively iterated over and cleaned), and the final two are trim and clean, which behave in the same way as earlier.

Any methods not found on this binput class will actually fall back to the laravel request class with a dynamic call function, so every other method on the request class is available in exactly the same way it would be on the Laravel request class.

Facades\Binput

This facade will dynamically pass static method calls to the 'binput' object in the ioc container which by default is the Binput class.

BinputServiceProvider

This class contains no public methods of interest. This class should be added to the providers array in config/app.php. This class will setup ioc bindings.

Real Examples

Here you can see an example of just how simple this package is to use.

// request input data: ['test' => '123', 'foo' => '<script>alert(\'bar\');</script>    ']

$input = Binput::all(); // ['test' => '123', 'foo' => '']

Security

If you discover a security vulnerability within this package, please send an email to [email protected]. All security vulnerabilities will be promptly addressed. You may view our full security policy here.

License

Laravel Binput is licensed under The MIT License (MIT).

For Enterprise

Available as part of the Tidelift Subscription

The maintainers of graham-campbell/binput and thousands of other packages are working with Tidelift to deliver commercial support and maintenance for the open source dependencies you use to build your applications. Save time, reduce risk, and improve code health, while paying the maintainers of the exact dependencies you use. Learn more.

More Repositories

1

Laravel-Markdown

A CommonMark wrapper for Laravel
PHP
1,309
star
2

Laravel-Throttle

A rate limiter for Laravel
PHP
700
star
3

Laravel-GitHub

A GitHub API bridge for Laravel
PHP
599
star
4

Laravel-Exceptions

Provides a powerful error response system for Laravel
PHP
588
star
5

Laravel-Flysystem

A Flysystem bridge for Laravel
PHP
484
star
6

Laravel-DigitalOcean

A DigitalOcean API bridge for Laravel
PHP
458
star
7

Result-Type

An implementation of the result type
PHP
453
star
8

Laravel-Manager

Providing some manager functionality for Laravel
PHP
385
star
9

Laravel-Security

A wrapper of voku/anti-xss for Laravel
PHP
227
star
10

Laravel-GitLab

A GitLab API bridge for Laravel
PHP
135
star
11

Guzzle-Factory

A simple Guzzle factory
PHP
91
star
12

Laravel-Bitbucket

A Bitbucket API bridge for Laravel
PHP
75
star
13

Laravel-TestBench

Providing some testing functionality for Laravel
PHP
49
star
14

Laravel-Example

PHP
30
star
15

Analyzer

Checks if referenced classes really exist
PHP
28
star
16

Packagist-Stats

A CLI Tool To Display Download Stats For Packagist Packages
PHP
27
star
17

Security-Core

A wrapper of voku/anti-xss for general use
PHP
23
star
18

GitHub-Notifications

Reduce your notification burden on GitHub
PHP
22
star
19

Cache-Plugin

A simple HTTP cache plugin with good defaults
PHP
16
star
20

Laravel-TestBench-Core

Providing some testing functionality for Laravel
PHP
14
star
21

Matrices

Adds matrix algebra to php
PHP
13
star
22

Envelope-Encryption

Symmetric envelope encryption using AWS KMS
PHP
9
star
23

Bounded-Cache

A bounded TTL PSR-16 cache implementation
PHP
9
star
24

Sudoku

An open source implementation of sudoku
Python
6
star
25

PHP8

Shell
4
star
26

GrahamCampbell

Hi there 👋
4
star