mirror of
https://github.com/symfony/recipes-contrib.git
synced 2026-09-11 15:16:55 +03:00
86 lines
5.1 KiB
JSON
86 lines
5.1 KiB
JSON
{
|
|
"manifests": {
|
|
"bel-consulting/kiwicaptcha-symfony": {
|
|
"manifest": {
|
|
"bundles": {
|
|
"BelConsulting\\KiwiCaptchaBundle\\KiwiCaptchaBundle": [
|
|
"all"
|
|
]
|
|
},
|
|
"copy-from-recipe": {
|
|
"config/": "%CONFIG_DIR%/"
|
|
},
|
|
"env": {
|
|
"KIWI_SECRET_KEY": "%generate(secret)%",
|
|
"KIWI_REDIS_DSN": "redis://127.0.0.1:6379/0",
|
|
"KIWI_PUBLIC_URL": "https://captcha.example.com"
|
|
}
|
|
},
|
|
"files": {
|
|
"config/packages/kiwicaptcha.yaml": {
|
|
"contents": [
|
|
"kiwi_captcha:",
|
|
" # Policy-level posture preset: balanced | privacy_strict | high_abuse |",
|
|
" # compatibility. The profile is the LOWEST-precedence configuration",
|
|
" # layer: it fills safe derived defaults for the safety-relevant knobs,",
|
|
" # and an explicit value in ANY config file always wins. An explicit",
|
|
" # `protection_profile: null` in a later layer (e.g. a prod overlay)",
|
|
" # clears the profile again. See docs/configuration.md \"Protection",
|
|
" # profiles\".",
|
|
" protection_profile: balanced",
|
|
"",
|
|
" # Required, min 16 bytes. The manifest writes the generated value",
|
|
" # into .env; replace it with `openssl rand -hex 32`.",
|
|
" secret_key: '%env(KIWI_SECRET_KEY)%'",
|
|
"",
|
|
" # Canonical public origin (required in production; the same-origin",
|
|
" # check compares against this value, never the Host header). The",
|
|
" # manifest declares the KIWI_PUBLIC_URL default in .env; credentials",
|
|
" # and environment-specific origins belong in your environment, never",
|
|
" # in source-controlled YAML. A literal override in this file is still",
|
|
" # possible (a clean https URL, no path, no credentials).",
|
|
" public_base_url: '%env(KIWI_PUBLIC_URL)%'",
|
|
"",
|
|
" # High-level Redis connection setting: when set, the bundle",
|
|
" # constructs the Redis-backed services itself from this DSN \u2014 the",
|
|
" # challenge storage (RedisStorage), the distributed issuance rate",
|
|
" # limiter, the Argon2id admission semaphore and (when risk is",
|
|
" # enabled) the risk state store. The client is built as a",
|
|
" # Predis\\Client, so predis/predis must be installed:",
|
|
" # composer require predis/predis",
|
|
" # Twelve-factor form: the DSN (credentials, private hosts, TLS, db",
|
|
" # selection) belongs in the environment \u2014 the manifest declares the",
|
|
" # KIWI_REDIS_DSN localhost default in .env. The bundle validates the",
|
|
" # resolved value when the client is constructed (redis:// or",
|
|
" # rediss:// with a host, fail-closed). A literal override in this",
|
|
" # file is still possible, e.g.",
|
|
" # redis://user:pass@host:port/0?prefix=kiwi.",
|
|
" redis_dsn: '%env(KIWI_REDIS_DSN)%'",
|
|
"",
|
|
" # Advanced escape hatch: an explicit service id always wins over the",
|
|
" # DSN for its knob. Define the service in config/services.yaml and",
|
|
" # uncomment to replace the DSN-built storage/client:",
|
|
" # storage: kiwicaptcha.storage.redis # a custom StorageInterface service",
|
|
" # redis_service: kiwicaptcha.redis_client # a custom \\Redis|Predis\\Client",
|
|
" # risk.redis_service: ... # a custom Predis\\Client for the risk state",
|
|
""
|
|
],
|
|
"executable": false
|
|
},
|
|
"config/routes/kiwicaptcha.yaml": {
|
|
"contents": [
|
|
"# The challenge endpoint (and the health routes) are auto-registered on",
|
|
"# a fresh app that never configured framework.router itself. When your",
|
|
"# app owns its router resource, import the bundle routes explicitly.",
|
|
"kiwi_captcha:",
|
|
" resource: '@KiwiCaptchaBundle/Resources/config/routes.php'",
|
|
""
|
|
],
|
|
"executable": false
|
|
}
|
|
},
|
|
"ref": "54d96969a398359596f0fe2d06ed1ab40f132274"
|
|
}
|
|
}
|
|
}
|