payloadshield / symfonyps
Symfony bundle for encrypting and decrypting HTTP payloads
Requires
- php: >=8.1
- payloadshield/comphpps: *
- symfony/config: ^6.4 || ^7.0 || ^8.0
- symfony/dependency-injection: ^6.4 || ^7.0 || ^8.0
- symfony/http-foundation: ^6.4 || ^7.0 || ^8.0
- symfony/http-kernel: ^6.4 || ^7.0 || ^8.0
Requires (Dev)
- phpunit/phpunit: ^10.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
README
PayloadShield SymfonyPS is a Symfony bundle that encrypts JSON responses, decrypts JSON requests, or does both using the handlers provided by ComPHPPS.
Install
composer require payloadshield/symfonyps
Register the bundle in config/bundles.php when Symfony Flex has not registered it:
PayloadShield\SymfonyPS\PayloadShieldBundle::class => ['all' => true],
Configure keys in config/packages/payload_shield.yaml:
payload_shield: default_handler: aes-gcm-256 key: '%env(PAYLOADSHIELD_KEY)%'
RSA, EC, and HPKE handlers additionally use private_key, public_key, ec_private_key, ec_public_key, hpke_private_key, and hpke_public_key. Values may be PEM contents or file paths.
Protect Routes
Set route defaults with the PayloadShield helper:
use PayloadShield\SymfonyPS\PayloadShield; $routes->add('secure_data', '/api/data') ->controller([DataController::class, 'show']) ->defaults(PayloadShield::encrypt('aes-gcm-256')); $routes->add('process_data', '/api/process') ->controller([DataController::class, 'process']) ->methods(['POST']) ->defaults(PayloadShield::decrypt('aes-gcm-256')); $routes->add('secure_process', '/api/secure-process') ->controller([DataController::class, 'process']) ->methods(['POST']) ->defaults(PayloadShield::crypt('aes-gcm-256'));
The encrypted request and response envelope is {"encrypted":"..."}. The encrypted request payload must decode to a JSON object or array.
Example App
See example/README.md for a runnable app covering all eight built-in handlers.