mirror of
https://github.com/symfony/recipes-contrib.git
synced 2026-09-12 15:46:52 +03:00
Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
5405fa6745 |
@@ -1,78 +0,0 @@
|
|||||||
{
|
|
||||||
"manifests": {
|
|
||||||
"acencyril/sentinelle-bundle": {
|
|
||||||
"manifest": {
|
|
||||||
"bundles": {
|
|
||||||
"Acencyril\\SentinelleBundle\\SentinelleBundle": [
|
|
||||||
"all"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"copy-from-recipe": {
|
|
||||||
"config/": "%CONFIG_DIR%/"
|
|
||||||
},
|
|
||||||
"env": {
|
|
||||||
"#1": "Where security alerts are sent.",
|
|
||||||
"SENTINELLE_ALERT_EMAIL": "admin@example.com",
|
|
||||||
"#2": "IPs or CIDRs, comma separated, that must never be blocked.",
|
|
||||||
"#3": "PUT YOUR OWN OUTBOUND ADDRESS HERE before going live:",
|
|
||||||
"#4": "without it, an automatic block can lock you out of your own site.",
|
|
||||||
"SENTINELLE_ALLOWLIST": ""
|
|
||||||
},
|
|
||||||
"post-install-output": [
|
|
||||||
" <bg=blue;fg=white>Sentinelle is installed.</> Three things before going live:",
|
|
||||||
"",
|
|
||||||
" * Set <comment>SENTINELLE_ALLOWLIST</comment> in your <comment>.env</comment> \u2014 at minimum your own",
|
|
||||||
" outbound address. Without it, an automatic block can lock you out of",
|
|
||||||
" your own site.",
|
|
||||||
"",
|
|
||||||
" * Create the schema:",
|
|
||||||
" <comment>php bin/console doctrine:migrations:diff</comment>",
|
|
||||||
" <comment>php bin/console doctrine:migrations:migrate</comment>",
|
|
||||||
"",
|
|
||||||
" * Check it can do its job:",
|
|
||||||
" <comment>php bin/console sentinelle:check</comment>",
|
|
||||||
"",
|
|
||||||
" Sentinelle starts in <comment>dry-run</comment>: it detects, logs and alerts, but blocks",
|
|
||||||
" nothing. Watch <comment>/admin/activity</comment> for a few days, then set",
|
|
||||||
" <comment>sentinelle.dry_run</comment> to <comment>false</comment>.",
|
|
||||||
"",
|
|
||||||
" And schedule the purge, without which strike counters never reset:",
|
|
||||||
" <comment>0 4 * * * php bin/console sentinelle:purge</comment>",
|
|
||||||
""
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"files": {
|
|
||||||
"config/packages/sentinelle.yaml": {
|
|
||||||
"contents": [
|
|
||||||
"sentinelle:",
|
|
||||||
" # Dry-run: Sentinelle detects, logs and alerts, but blocks NOTHING.",
|
|
||||||
" # Nobody wires automatic blocking into a production site without knowing",
|
|
||||||
" # what it will shut out. Watch the dashboard for a few days, ask yourself",
|
|
||||||
" # \"would I have wanted to block that one?\", then switch it off.",
|
|
||||||
" dry_run: true",
|
|
||||||
" alert:",
|
|
||||||
" recipient: '%env(SENTINELLE_ALERT_EMAIL)%'",
|
|
||||||
" access:",
|
|
||||||
" role: ROLE_ADMIN",
|
|
||||||
" never_block:",
|
|
||||||
" # At minimum your own outbound address. Private ranges are protected",
|
|
||||||
" # by default, but yours is not: one wrong move locks you out.",
|
|
||||||
" ips: '%env(default::SENTINELLE_ALLOWLIST)%'",
|
|
||||||
""
|
|
||||||
],
|
|
||||||
"executable": false
|
|
||||||
},
|
|
||||||
"config/routes/sentinelle.yaml": {
|
|
||||||
"contents": [
|
|
||||||
"sentinelle:",
|
|
||||||
" resource: '@SentinelleBundle/config/routes.php'",
|
|
||||||
" type: php",
|
|
||||||
""
|
|
||||||
],
|
|
||||||
"executable": false
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"ref": "f8fdd404ae3f91c5c64a07c46a00a032767d006b"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,63 @@
|
|||||||
|
{
|
||||||
|
"manifests": {
|
||||||
|
"codein/recaptcha-enterprise-bundle": {
|
||||||
|
"manifest": {
|
||||||
|
"bundles": {
|
||||||
|
"Codein\\RecaptchaEnterpriseBundle\\CodeinRecaptchaEnterpriseBundle": [
|
||||||
|
"all"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"copy-from-recipe": {
|
||||||
|
"config/": "%CONFIG_DIR%/"
|
||||||
|
},
|
||||||
|
"env": {
|
||||||
|
"#1": "Create the key and read the project id in the reCAPTCHA Enterprise console:",
|
||||||
|
"#2": "https://console.cloud.google.com/security/recaptcha",
|
||||||
|
"#3": "The score and checkbox challenges each need their own kind of site key.",
|
||||||
|
"CODEIN_RECAPTCHA_ENTERPRISE_PROJECT_ID": "",
|
||||||
|
"CODEIN_RECAPTCHA_ENTERPRISE_SITE_KEY": "",
|
||||||
|
"CODEIN_RECAPTCHA_ENTERPRISE_API_KEY": ""
|
||||||
|
},
|
||||||
|
"post-install-output": [
|
||||||
|
" * <fg=blue>Set</> the <comment>CODEIN_RECAPTCHA_ENTERPRISE_*</> variables in <comment>.env.local</>",
|
||||||
|
"",
|
||||||
|
" * <fg=blue>Add</> <comment>two script tags</> to your layout \u2014 the bundle adds neither. Without them every",
|
||||||
|
" submission is refused as <comment>MISSING</>:",
|
||||||
|
" <comment>{{ asset('bundles/codeinrecaptchaenterprise/recaptcha-enterprise.js') }}</>, and Google's",
|
||||||
|
" <comment>enterprise.js</>, the latter only <comment>after the visitor has consented</>:",
|
||||||
|
" <comment>https://github.com/Codein-Labs/recaptcha-enterprise-bundle#adding-the-scripts-to-your-layout</>",
|
||||||
|
"",
|
||||||
|
" * <fg=blue>Read</> <comment>Choosing the challenge</> before creating the site key: the score and checkbox",
|
||||||
|
" challenges need different key types",
|
||||||
|
"",
|
||||||
|
" * Assessments are <comment>disabled in the test environment</>, where no browser can solve the challenge"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"files": {
|
||||||
|
"config/packages/codein_recaptcha_enterprise.yaml": {
|
||||||
|
"contents": [
|
||||||
|
"codein_recaptcha_enterprise:",
|
||||||
|
" project_id: '%env(CODEIN_RECAPTCHA_ENTERPRISE_PROJECT_ID)%'",
|
||||||
|
" site_key: '%env(CODEIN_RECAPTCHA_ENTERPRISE_SITE_KEY)%'",
|
||||||
|
" api_key: '%env(CODEIN_RECAPTCHA_ENTERPRISE_API_KEY)%'",
|
||||||
|
" #challenge: checkbox # score (default) or checkbox, each needs its own kind of site key",
|
||||||
|
" #min_score: 0 # 0 disables the score check, which is what the checkbox challenge wants",
|
||||||
|
" #on_error: allow # deny (default) refuses the token when Google cannot be reached",
|
||||||
|
"",
|
||||||
|
"# A test run has no browser to solve the challenge, so every submission would be refused.",
|
||||||
|
"when@test:",
|
||||||
|
" codein_recaptcha_enterprise:",
|
||||||
|
" enabled: false",
|
||||||
|
"",
|
||||||
|
"#when@dev:",
|
||||||
|
"# codein_recaptcha_enterprise:",
|
||||||
|
"# enabled: false",
|
||||||
|
""
|
||||||
|
],
|
||||||
|
"executable": false
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"ref": "3e258fc4d39c26c29f42366af814e902418daf71"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
+4
-4
@@ -1,8 +1,8 @@
|
|||||||
{
|
{
|
||||||
"aliases": [],
|
"aliases": [],
|
||||||
"recipes": {
|
"recipes": {
|
||||||
"acencyril/sentinelle-bundle": [
|
"codein/recaptcha-enterprise-bundle": [
|
||||||
"0.3"
|
"1.0"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"recipe-conflicts": [],
|
"recipe-conflicts": [],
|
||||||
@@ -12,9 +12,9 @@
|
|||||||
"_links": {
|
"_links": {
|
||||||
"repository": "github.com/symfony/recipes-contrib",
|
"repository": "github.com/symfony/recipes-contrib",
|
||||||
"origin_template": "{package}:{version}@github.com/symfony/recipes-contrib:main",
|
"origin_template": "{package}:{version}@github.com/symfony/recipes-contrib:main",
|
||||||
"recipe_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2040/{package_dotted}.{version}.json",
|
"recipe_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2045/{package_dotted}.{version}.json",
|
||||||
"recipe_template_relative": "{package_dotted}.{version}.json",
|
"recipe_template_relative": "{package_dotted}.{version}.json",
|
||||||
"archived_recipes_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2040/archived/{package_dotted}/{ref}.json",
|
"archived_recipes_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2045/archived/{package_dotted}/{ref}.json",
|
||||||
"archived_recipes_template_relative": "archived/{package_dotted}/{ref}.json"
|
"archived_recipes_template_relative": "archived/{package_dotted}/{ref}.json"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user