mirror of
https://github.com/symfony/recipes-contrib.git
synced 2026-09-11 23:26:40 +03:00
Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
358c4178dd |
@@ -0,0 +1,78 @@
|
||||
{
|
||||
"manifests": {
|
||||
"acencyril/sentinelle-bundle": {
|
||||
"manifest": {
|
||||
"bundles": {
|
||||
"Acencyril\\SentinelleBundle\\SentinelleBundle": [
|
||||
"all"
|
||||
]
|
||||
},
|
||||
"copy-from-recipe": {
|
||||
"config/": "%CONFIG_DIR%/"
|
||||
},
|
||||
"env": {
|
||||
"#1": "Where security alerts are sent.",
|
||||
"SENTINELLE_ALERT_EMAIL": "admin@example.com",
|
||||
"#2": "IPs or CIDRs, comma separated, that must never be blocked.",
|
||||
"#3": "PUT YOUR OWN OUTBOUND ADDRESS HERE before going live:",
|
||||
"#4": "without it, an automatic block can lock you out of your own site.",
|
||||
"SENTINELLE_ALLOWLIST": ""
|
||||
},
|
||||
"post-install-output": [
|
||||
" <bg=blue;fg=white>Sentinelle is installed.</> Three things before going live:",
|
||||
"",
|
||||
" * Set <comment>SENTINELLE_ALLOWLIST</comment> in your <comment>.env</comment> \u2014 at minimum your own",
|
||||
" outbound address. Without it, an automatic block can lock you out of",
|
||||
" your own site.",
|
||||
"",
|
||||
" * Create the schema:",
|
||||
" <comment>php bin/console doctrine:migrations:diff</comment>",
|
||||
" <comment>php bin/console doctrine:migrations:migrate</comment>",
|
||||
"",
|
||||
" * Check it can do its job:",
|
||||
" <comment>php bin/console sentinelle:check</comment>",
|
||||
"",
|
||||
" Sentinelle starts in <comment>dry-run</comment>: it detects, logs and alerts, but blocks",
|
||||
" nothing. Watch <comment>/admin/activity</comment> for a few days, then set",
|
||||
" <comment>sentinelle.dry_run</comment> to <comment>false</comment>.",
|
||||
"",
|
||||
" And schedule the purge, without which strike counters never reset:",
|
||||
" <comment>0 4 * * * php bin/console sentinelle:purge</comment>",
|
||||
""
|
||||
]
|
||||
},
|
||||
"files": {
|
||||
"config/packages/sentinelle.yaml": {
|
||||
"contents": [
|
||||
"sentinelle:",
|
||||
" # Dry-run: Sentinelle detects, logs and alerts, but blocks NOTHING.",
|
||||
" # Nobody wires automatic blocking into a production site without knowing",
|
||||
" # what it will shut out. Watch the dashboard for a few days, ask yourself",
|
||||
" # \"would I have wanted to block that one?\", then switch it off.",
|
||||
" dry_run: true",
|
||||
" alert:",
|
||||
" recipient: '%env(SENTINELLE_ALERT_EMAIL)%'",
|
||||
" access:",
|
||||
" role: ROLE_ADMIN",
|
||||
" never_block:",
|
||||
" # At minimum your own outbound address. Private ranges are protected",
|
||||
" # by default, but yours is not: one wrong move locks you out.",
|
||||
" ips: '%env(default::SENTINELLE_ALLOWLIST)%'",
|
||||
""
|
||||
],
|
||||
"executable": false
|
||||
},
|
||||
"config/routes/sentinelle.yaml": {
|
||||
"contents": [
|
||||
"sentinelle:",
|
||||
" resource: '@SentinelleBundle/config/routes.php'",
|
||||
" type: php",
|
||||
""
|
||||
],
|
||||
"executable": false
|
||||
}
|
||||
},
|
||||
"ref": "f8fdd404ae3f91c5c64a07c46a00a032767d006b"
|
||||
}
|
||||
}
|
||||
}
|
||||
+4
-4
@@ -1,8 +1,8 @@
|
||||
{
|
||||
"aliases": [],
|
||||
"recipes": {
|
||||
"zestly/dev-login-bundle": [
|
||||
"0.1"
|
||||
"acencyril/sentinelle-bundle": [
|
||||
"0.3"
|
||||
]
|
||||
},
|
||||
"recipe-conflicts": [],
|
||||
@@ -12,9 +12,9 @@
|
||||
"_links": {
|
||||
"repository": "github.com/symfony/recipes-contrib",
|
||||
"origin_template": "{package}:{version}@github.com/symfony/recipes-contrib:main",
|
||||
"recipe_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2030/{package_dotted}.{version}.json",
|
||||
"recipe_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2040/{package_dotted}.{version}.json",
|
||||
"recipe_template_relative": "{package_dotted}.{version}.json",
|
||||
"archived_recipes_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2030/archived/{package_dotted}/{ref}.json",
|
||||
"archived_recipes_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2040/archived/{package_dotted}/{ref}.json",
|
||||
"archived_recipes_template_relative": "archived/{package_dotted}/{ref}.json"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,71 +0,0 @@
|
||||
{
|
||||
"manifests": {
|
||||
"zestly/dev-login-bundle": {
|
||||
"manifest": {
|
||||
"bundles": {
|
||||
"Zestly\\DevLoginBundle\\ZestlyDevLoginBundle": [
|
||||
"dev"
|
||||
]
|
||||
},
|
||||
"copy-from-recipe": {
|
||||
"config/": "%CONFIG_DIR%/"
|
||||
},
|
||||
"post-install-output": [
|
||||
" * Dev login is ready. Start your server and open:",
|
||||
"",
|
||||
" <fg=yellow>/_dev/login</> list the identities you can become",
|
||||
" <fg=yellow>/_dev/login/{identifier}</> log in as one of them, no password",
|
||||
"",
|
||||
" * List them from the console instead:",
|
||||
"",
|
||||
" <fg=yellow>php bin/console dev:login</>",
|
||||
"",
|
||||
" * Declare who shows up in that list in <comment>config/packages/zestly_dev_login.yaml</>.",
|
||||
"",
|
||||
" * This grants password-free login to any account your user provider accepts.",
|
||||
" It registers no services outside the dev environment, and its routes are imported",
|
||||
" under <comment>when@dev:</> so they do not exist in a production router.",
|
||||
"",
|
||||
" * Docs: <comment>https://github.com/ZestlyDigital/dev-login-bundle</>"
|
||||
]
|
||||
},
|
||||
"files": {
|
||||
"config/packages/zestly_dev_login.yaml": {
|
||||
"contents": [
|
||||
"when@dev:",
|
||||
" zestly_dev_login:",
|
||||
" # The identities offered by GET /_dev/login and `bin/console dev:login`.",
|
||||
" #",
|
||||
" # There is no sensible default for this \u2014 it depends entirely on your fixtures \u2014 which",
|
||||
" # is why it is the one setting this recipe writes. Everything else the bundle exposes",
|
||||
" # already has a working default and is documented in the README.",
|
||||
" #",
|
||||
" # This is a convenience menu, not a whitelist: any identifier your application's user",
|
||||
" # provider accepts will work, and listing one here grants nothing on its own.",
|
||||
" #",
|
||||
" # To build the list from your fixtures, a repository, or per-subdomain in a multi-tenant",
|
||||
" # app, implement Zestly\\DevLoginBundle\\Identity\\IdentityProviderInterface and alias it \u2014",
|
||||
" # it receives the current Request.",
|
||||
" identities: []",
|
||||
" # - { identifier: 'admin@example.com', label: 'Admin', roles: ['ROLE_ADMIN'] }",
|
||||
" # - { identifier: 'user@example.com', label: 'Regular user' }",
|
||||
""
|
||||
],
|
||||
"executable": false
|
||||
},
|
||||
"config/routes/zestly_dev_login.yaml": {
|
||||
"contents": [
|
||||
"# Dev login endpoints. The `when@dev:` guard is one of the bundle's safety gates \u2014 a production",
|
||||
"# router never learns these paths exist. Drop the guard and you drop that gate.",
|
||||
"when@dev:",
|
||||
" zestly_dev_login:",
|
||||
" resource: '@ZestlyDevLoginBundle/config/routes.php'",
|
||||
""
|
||||
],
|
||||
"executable": false
|
||||
}
|
||||
},
|
||||
"ref": "e15edc988e1ac029ea0ff9fe98ad4da43da4330d"
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user