jord-jd / laravel-route-restrictor
Laravel middleware to restrict a site or specific routes using HTTP basic authentication
Package info
github.com/Jord-JD/laravel-route-restrictor
pkg:composer/jord-jd/laravel-route-restrictor
Fund package maintenance!
Requires
- php: >=5.5.9
- laravel/framework: ^5.1||^6.0||^7.0||^8.0||^9.0||^10.0||^11.0||^12.0||^13.0
Requires (Dev)
- phpunit/phpunit: ^4.8||^9.6||^12.0
Replaces
README
Laravel Route Restrictor is middleware designed to restrict an entire site or specific routes using HTTP Basic Authentication. It is compatible with Laravel 5.1 through 13.
Setup
- Run
composer require jord-jd/laravel-route-restrictor. - On Laravel 5.4 and earlier, add
JordJD\LaravelRouteRestrictor\Providers\LaravelRouteRestrictorServiceProvider::classto the$providersarray in yourconfig/app.phpfile. Newer Laravel versions discover it automatically. - Run
php artisan vendor:publish --provider="JordJD\LaravelRouteRestrictor\Providers\LaravelRouteRestrictorServiceProvider". - Add
\JordJD\LaravelRouteRestrictor\Http\Middleware\BasicAuthentication::classto the$middlewarearray in yourapp/Http/Kernel.phpfile. - Add
'routeRestrictor' => \JordJD\LaravelRouteRestrictor\Http\Middleware\BasicAuthentication::classto the$routeMiddlewarearray in yourapp/Http/Kernel.phpfile. - If a CGI/FastCGI server does not forward the
Authorizationheader, configure the server to forward it. For Apache, addRewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]immediately belowRewriteEngine Oninpublic/.htaccess.
The middleware reads credentials from the request rather than PHP globals, so it also works safely with long-running application servers and test clients.
Global restriction
In order to restrict all routes in your Laravel application, just add the global username and password to your .env file as follows. Ensure you change the username and password values.
ROUTE_RESTRICTOR_GLOBAL_USERNAME=username
ROUTE_RESTRICTOR_GLOBAL_PASSWORD=password
Your entire application will then be protected by these details, unless a route specific restriction is in place.
Alternatively, you can modify the global restriction username and password in your config/laravel-route-restrictor.php configuration file.
Restricting specific routes
To restrict specific routes, you must edit your routes file. Simply surround the route or routes you want to restrict with the following route group code. Ensure you change the username and password middleware parameters.
Route::group(['middleware' => 'routeRestrictor:username,password'], function () { // Route(s) to restrict go here });
Note: If you have both route specific restrictions and a global restriction, both will work, but route specific restrictions will take priority.
Excluding specific routes from restriction
If you wish to exclude one or more routes from restriction, you must edit your routes file. Simply surround the route or routes you want to exclude with the following route group code.
Route::group(['middleware' => 'routeRestrictor:disable'], function () { // Route(s) to exclude from restriction go here });