mirror of
https://github.com/symfony/recipes-contrib.git
synced 2026-09-11 15:16:55 +03:00
Compare commits
2
Commits
34b440b9b5
...
07f7809541
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
07f7809541 | ||
|
|
42c7572f9a |
@@ -0,0 +1,14 @@
|
||||
sentinelle:
|
||||
# Dry-run: Sentinelle detects, logs and alerts, but blocks NOTHING.
|
||||
# Nobody wires automatic blocking into a production site without knowing
|
||||
# what it will shut out. Watch the dashboard for a few days, ask yourself
|
||||
# "would I have wanted to block that one?", then switch it off.
|
||||
dry_run: true
|
||||
alert:
|
||||
recipient: '%env(SENTINELLE_ALERT_EMAIL)%'
|
||||
access:
|
||||
role: ROLE_ADMIN
|
||||
never_block:
|
||||
# At minimum your own outbound address. Private ranges are protected
|
||||
# by default, but yours is not: one wrong move locks you out.
|
||||
ips: '%env(default::SENTINELLE_ALLOWLIST)%'
|
||||
@@ -0,0 +1,3 @@
|
||||
sentinelle:
|
||||
resource: '@SentinelleBundle/config/routes.php'
|
||||
type: php
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"bundles": {
|
||||
"Acencyril\\SentinelleBundle\\SentinelleBundle": [
|
||||
"all"
|
||||
]
|
||||
},
|
||||
"copy-from-recipe": {
|
||||
"config/": "%CONFIG_DIR%/"
|
||||
},
|
||||
"env": {
|
||||
"#1": "Where security alerts are sent.",
|
||||
"SENTINELLE_ALERT_EMAIL": "admin@example.com",
|
||||
"#2": "IPs or CIDRs, comma separated, that must never be blocked.",
|
||||
"#3": "PUT YOUR OWN OUTBOUND ADDRESS HERE before going live:",
|
||||
"#4": "without it, an automatic block can lock you out of your own site.",
|
||||
"SENTINELLE_ALLOWLIST": ""
|
||||
},
|
||||
"post-install-output": [
|
||||
" <bg=blue;fg=white>Sentinelle is installed.</> Three things before going live:",
|
||||
"",
|
||||
" * Set <comment>SENTINELLE_ALLOWLIST</comment> in your <comment>.env</comment> — at minimum your own",
|
||||
" outbound address. Without it, an automatic block can lock you out of",
|
||||
" your own site.",
|
||||
"",
|
||||
" * Create the schema:",
|
||||
" <comment>php bin/console doctrine:migrations:diff</comment>",
|
||||
" <comment>php bin/console doctrine:migrations:migrate</comment>",
|
||||
"",
|
||||
" * Check it can do its job:",
|
||||
" <comment>php bin/console sentinelle:check</comment>",
|
||||
"",
|
||||
" Sentinelle starts in <comment>dry-run</comment>: it detects, logs and alerts, but blocks",
|
||||
" nothing. Watch <comment>/admin/activity</comment> for a few days, then set",
|
||||
" <comment>sentinelle.dry_run</comment> to <comment>false</comment>.",
|
||||
"",
|
||||
" And schedule the purge, without which strike counters never reset:",
|
||||
" <comment>0 4 * * * php bin/console sentinelle:purge</comment>",
|
||||
""
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,2 @@
|
||||
imports:
|
||||
- { resource: "@OdiseoSyliusRbacPlugin/config/config.yaml" }
|
||||
@@ -0,0 +1,3 @@
|
||||
odiseo_sylius_rbac_admin:
|
||||
resource: "@OdiseoSyliusRbacPlugin/config/routes/admin.yaml"
|
||||
prefix: /admin
|
||||
@@ -0,0 +1,8 @@
|
||||
{
|
||||
"bundles": {
|
||||
"Odiseo\\SyliusRbacPlugin\\OdiseoSyliusRbacPlugin": ["all"]
|
||||
},
|
||||
"copy-from-recipe": {
|
||||
"config/": "%CONFIG_DIR%/"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,18 @@
|
||||
<bg=blue;fg=white> </>
|
||||
<bg=blue;fg=white> What's next? </>
|
||||
<bg=blue;fg=white> </>
|
||||
|
||||
* <fg=blue>Make</> your AdminUser administration-role aware: add
|
||||
<comment>AdministrationRoleAwareInterface</> and <comment>AdministrationRoleAwareTrait</>
|
||||
to your <comment>AdminUser</> entity. This plugin cannot do it for you -- that class is
|
||||
yours, and may already extend or implement other things.
|
||||
|
||||
* <fg=blue>Update</> your database schema:
|
||||
<comment>bin/console doctrine:migrations:migrate</>
|
||||
|
||||
* <fg=blue>Grant</> yourself access. A fresh install denies every administrator
|
||||
everything, including the screen that assigns roles:
|
||||
<comment>bin/console odiseo:rbac:grant <username-or-email> super_admin --create</>
|
||||
|
||||
* <fg=blue>Read</> the full installation guide, including the AdminUser snippet, at
|
||||
<comment>https://github.com/odiseoteam/SyliusRbacPlugin/blob/master/doc/installation.md</>
|
||||
Reference in New Issue
Block a user