Changelog
Versi terbaru: v2.1.0 · Packagist · Repositori GitHub
All notable changes to robyajo/laravel-security-monitor will be documented in this file.
[2.1.0] - 2026-10-09
Bagian berjudul “[2.1.0] - 2026-10-09”- Hardened Apache 2 VirtualHost Configuration (
stubs/apache2.conf.stub):- Menyediakan template VirtualHost Apache 2 hardened siap pakai untuk server Ubuntu / Debian / CentOS.
- Tag vendor publish baru:
php artisan vendor:publish --tag=security-apache(menghasilkan berkasapache2.confdi root aplikasi host). - Terintegrasi penuh ke dalam perintah instalasi
php artisan security:installdan grup tag--tag=security-all. - Opsi CLI baru:
--without-apachepadaphp artisan security:installuntuk melewati publikasiapache2.conf. - Fitur pengamanan VirtualHost mencakup:
- Mitigasi Slowloris DoS via
mod_reqtimeout(header=15-30,MinRate=500 body=15,MinRate=500). - Buffer request body (5MB) dan header buffer (
LimitRequestFieldSize 32768) untuk mencegah DoS dan error token JWT/Cookie besar. - Penolakan HTTP method berisiko (
TRACE,TRACK) untuk mitigasi Cross-Site Tracing (XST). - Header keamanan lengkap:
X-Frame-Options,X-Content-Type-Options: nosniff,Referrer-Policy,Permissions-Policy, dan penyembunyianX-Powered-By. - Resolusi IP asli via
mod_remoteip(X-Forwarded-For/CF-Connecting-IP). - Restriksi eksekusi PHP: hanya
/index.phpyang diizinkan dieksekusi, semua berkas.phplain ditolak dengan 403 Forbidden. - Pencegahan eksekusi berkas double extension (
.php.jpg,.phtml.zip, dll.). - Sandboxing folder
/storage/denganContent-Security-Policy: sandboxuntuk mencegah eksekusi polyglot/SVG berbahaya. - Integrasi PHP-FPM aman melalui
mod_proxy_fcgi.
- Mitigasi Slowloris DoS via
[2.0.10] - 2026-10-09
Bagian berjudul “[2.0.10] - 2026-10-09”Changed
Bagian berjudul “Changed”- Hardening Template Nginx (
stubs/nginx.conf.stub):- Peningkatan FastCGI buffer:
fastcgi_buffers 16 16k;,fastcgi_buffer_size 32k;,fastcgi_busy_buffers_size 64k;untuk mencegah 502 Bad Gateway saat respons besar. - Penambahan buffer header klien (
client_header_buffer_size 16k;,large_client_header_buffers 4 32k;). - Penambahan timeout mitigasi Slowloris DoS (
client_body_timeout 15s;,client_header_timeout 15s;,send_timeout 15s;). - Restriksi HTTP method (
GET|HEAD|POST|PUT|PATCH|DELETE|OPTIONS). - Blueprint pemulihan real IP dari reverse proxy / Cloudflare / Docker.
- Peningkatan FastCGI buffer:
[2.0.9] - 2026-10-05
Bagian berjudul “[2.0.9] - 2026-10-05”- Kompatibilitas CI & Test Matrix L10 - L13:
- Menambahkan dependensi
guzzlehttp/guzzle: ^7.8|^8.0padacomposer.jsonuntuk menjamin ketersediaan PSR-7 Response saat pengujianHttp::fake()dan fiturVersionCheckServicepada lingkungan Laravel 10. - Memperbaiki analisis statis PHPStan pada evaluasi tipe dinamis
LoginThrottleServicedanSecurityInstallCommand. - Mengoptimalkan assertion command options pada
SecurityInstallAutoInjectTest.
- Menambahkan dependensi
[2.0.8] - 2026-10-05
Bagian berjudul “[2.0.8] - 2026-10-05”-
Pemeriksaan Versi Otomatis & Notifikasi Upgrade di Terminal (
php artisan serve&composer run dev):- Secara otomatis memeriksa apakah terdapat versi rilis terbaru di Packagist/GitHub saat pengembang menjalankan
php artisan serveataucomposer run dev(artisan dev). - Menampilkan notifikasi visual di terminal konsol yang elegan dan informatif jika versi baru telah dirilis, lengkap dengan saran perintah upgrade.
- Pemeriksaan dirancang sangat ringan, non-blocking (timeout 2 detik), dan di-cache selama 1 jam (
SECURITY_VERSION_CHECK_CACHE_TTL=3600) sehingga tidak pernah memperlambat atau mengganggu startup server. - Dapat diaktifkan/dinonaktifkan melalui konfigurasi
security.version_check.enabledatau variabel.env:SECURITY_VERSION_CHECK_ENABLED=true.
- Secara otomatis memeriksa apakah terdapat versi rilis terbaru di Packagist/GitHub saat pengembang menjalankan
-
Perintah Baru
php artisan security:upgrade:- Perintah artisan terpadu untuk memeriksa, memperbarui, dan menyinkronkan seluruh komponen package:
php artisan security:upgrade: Memperbarui package via Composer (composer update robyajo/laravel-security-monitor), menerapkan migrasi database terbaru (php artisan migrate), menyinkronkan rute kustom (routes/security.php&routes/security-api.php), menyinkronkan tampilan dashboard monitoring (Blade/Livewire & React/TSX), serta membersihkan cache framework.- Opsi
--check: Hanya memeriksa status versi tanpa menjalankan proses pembaruan. - Opsi
--force: Memaksa pembaruan dan sinkronisasi aset meskipun sudah di versi terbaru. - Opsi
--no-composer: Melewati pembaruan Composer (hanya sinkronisasi aset lokal). - Opsi
--no-migrate: Melewati eksekusi migrasi database. - Opsi
--sync-routes&--sync-views: Memaksa pembaruan berkas rute dan tampilan dashboard.
- Perintah artisan terpadu untuk memeriksa, memperbarui, dan menyinkronkan seluruh komponen package:
-
Integrasi Informasi Versi pada Dashboard Pengaturan & REST API:
- Halaman Pengaturan Keamanan (
/security/settings) pada Livewire dan React kini menampilkan status versi aktif dan banner notifikasi pembaruan secara visual. - Endpoint REST API
GET /api/security/settingsmenyertakan metadataversion(current,latest,update_available).
- Halaman Pengaturan Keamanan (
[2.0.7] - 2026-10-05
Bagian berjudul “[2.0.7] - 2026-10-05”- Interactive Security Settings Page & Dynamic Configuration (Livewire, React, & REST API):
- Added dedicated Security Settings dashboard page accessible via
/security/settingsin both Livewire (pages/security/settings.blade.php) and React (pages/security/settings.tsx). - Added Settings link (⚙️) to the sidebar navigation in both Blade and React dashboard layouts.
- Interactive radio cards allowing administrators to configure blocking scope with clear visual guidance:
- Isolasi Perangkat Saja (
device) (Default / Rekomendasi): Only quarantines the offending device based on Device ID / Fingerprint / LAN IP, keeping innocent users sharing the same WiFi or NAT router completely safe. - Seluruh IP Router Publik (
ip): Quarantines the entire public router IP address.
- Isolasi Perangkat Saja (
- Dynamic configuration controls for:
- Automatic blocking scope (
auto_block_scope:deviceorip) - Zero tolerance instant blocking scope (
instant_block_scope:deviceorip) - Threshold count (
auto_block_threshold) - Accumulation window in minutes (
auto_block_window) - Quarantine duration in hours (
auto_block_duration) - Zero tolerance instant duration (
instant_block_duration) - HTTP 403 block enforcement master toggle (
block_enforcement)
- Automatic blocking scope (
- Dynamic multi-layer persistence:
SecuritySettingdatabase model/migration, high-performance in-memory and Cache layer, with automatic.envsynchronization. - Headless REST API endpoints:
GET /api/security/settings(retrieves current configuration)POST /api/security/settings(updates and applies settings with zero downtime)
- Added comprehensive feature tests in
tests/Feature/SecuritySettingsTest.php.
- Added dedicated Security Settings dashboard page accessible via
[2.0.6] - 2026-10-05
Bagian berjudul “[2.0.6] - 2026-10-05”- Device-Scoped Automatic & Instant Blocking (WiFi & NAT Router Isolation):
- Enforced device-level isolation for both threshold-based automatic blocking (
autoBlockIfNeeded) and zero-tolerance instant blocking (blockImmediately), ensuring that only the specific attacking device is quarantined rather than blocking the entire public router IP or office/cafe WiFi network. - Innocent users and colleagues sharing the same NAT public IP address can continue accessing the application without being affected or receiving HTTP 403 Forbidden.
- Added configurable blocking scopes in
config/security.phpandstubs/env.stub:SECURITY_AUTO_BLOCK_SCOPE=device(options:deviceorip, default:device).SECURITY_INSTANT_BLOCK_SCOPE=device(options:deviceorip, default:device).
- Deterministic client device fingerprinting (
generateDeviceFingerprint()): automatically synthesizes client identifiers (dev_*) from User-Agent, language, and client platform hints when custom headers (X-Device-Id,X-Client-Id) are not explicitly sent. - Persistent device cookie attachment:
BlockIpAddressmiddleware attaches anapp_device_idcookie to responses (including 403 Forbidden response pages) to guarantee seamless device tracking across subsequent visits. - Updated
LogFailedLoginAttemptandLoginThrottleServiceto track and pass device IDs and private LAN IPs discovered via WebRTC to brute-force lockout evaluations. - Added end-to-end feature tests in
tests/Feature/DeviceLevelBlockingTest.phpverifying that two clients on the identical public router IP (REMOTE_ADDR) are isolated so that the attacker receives 403 Forbidden while the innocent device receives 200 OK.
- Enforced device-level isolation for both threshold-based automatic blocking (
[2.0.5] - 2026-10-05
Bagian berjudul “[2.0.5] - 2026-10-05”- Automated API Setup & Customizable Route Files (
routes/security.php&routes/security-api.php):- Automatically checks and executes
php artisan install:apiduringsecurity:installif API routes are not yet initialized in Laravel 11/12/13 host applications. - Generates
routes/security-api.phpfor headless REST API endpoints and wires it intoroutes/api.php(require __DIR__.'/security-api.php';). - Generates
routes/security.phpfor web dashboard routes and wires it intoroutes/web.php(require __DIR__.'/security.php';). - Web routes in
routes/security.phprender directly to views (pages::security.*/resources/views/pages/security/*for Livewire/Blade or Inertia controllers for React) so developers have full control to customize URL prefixes, middleware, layout wrappers, and custom pages. - Added
security-routes,security-routes-web, andsecurity-routes-apipublication tags tophp artisan vendor:publish. - Added
--without-routesand--without-apiflags tophp artisan security:install. - Smart route loading in
SecurityMonitorServiceProvider: prioritized host route files if customized and prevents route duplication with hostroutes/web.phpandroutes/api.php.
- Automatically checks and executes
[2.0.4] - 2026-10-05
Bagian berjudul “[2.0.4] - 2026-10-05”- Pure Vanilla CSS Architecture for Dashboard Views:
- Migrated both Blade (Livewire) and React (TSX) dashboard stubs to pure Vanilla CSS.
- Eliminated external UI library dependencies (removed Livewire Flux UI, Shadcn UI,
@/lib/utils, andsonner). - Added standalone
security.cssstylesheet and zero-dependencyui.tsxhelper components (Card,Button,Badge,Input,Label). - Unified themeable CSS Custom Properties (
--sec-*) with built-in automatic dark mode (prefers-color-scheme: darkand.dark/[data-theme="dark"]). - 100% responsive layout across mobile, tablet, and desktop viewports with accessible modal dialogs and pure CSS trend chart bars.
[2.0.3] - 2026-10-05
Bagian berjudul “[2.0.3] - 2026-10-05”- Automated Host Setup in
security:install:- Automatically detects and injects the
HasSecurityRelationstrait and import intoapp/Models/User.php. - Automatically registers WAF middlewares (
BlockIpAddressandDetectSecurityThreats) inbootstrap/app.php(Laravel 11 & 12) orapp/Http/Kernel.php(Laravel 10). - Both injections are idempotent and preserve existing code formatting and PHPDoc tags.
- Added
--without-user-traitand--without-middlewareflags to bypass automatic registration if needed.
- Automatically detects and injects the
[2.0.2] - 2026-10-04
Bagian berjudul “[2.0.2] - 2026-10-04”- Blade & TSX Starter Kit Tags:
- Added
--with-blade,--with-tsx, and--with-allflags tophp artisan security:installalongside interactive stack selection. - Added
starterkit-blade,starterkit-tsx,starterkit-all,security-dashboard-blade,security-dashboard-tsx, andsecurity-dashboard-allpublication tags. - Enforced authentication and login requirement across all
/securitymonitoring routes.
- Added
[2.0.1] - 2026-10-03
Bagian berjudul “[2.0.1] - 2026-10-03”Changed
Bagian berjudul “Changed”- Refinements to post-2.0.0 headless architecture and route bindings.
[2.0.0] - 2026-10-03
Bagian berjudul “[2.0.0] - 2026-10-03”Changed
Bagian berjudul “Changed”- BREAKING — version corrected to a major. Removing the CAPTCHA subsystem
deletes public API (
CaptchaService,ValidCaptcha,CaptchaApiController), routes, config keys, andCAPTCHA_*environment variables, so it is a breaking change. The same removal was briefly tagged1.1.4;2.0.0is the canonical release. See the1.1.4entry below for the full list of removals.
[1.1.4] - 2026-10-03
Bagian berjudul “[1.1.4] - 2026-10-03”Removed
Bagian berjudul “Removed”- CAPTCHA subsystem removed. The zero-dependency SVG CAPTCHA has been
dropped to keep the package focused on WAF/threat protection. Deleted:
CaptchaService,ValidCaptcharule,CaptchaApiController, the/api/security/captchaendpoints, thesecurity.captchaconfig block, and theCAPTCHA_*environment variables. Login brute-force protection is still provided by the multi-tier stepped login lockout.
[1.1.3] - 2026-10-03
Bagian berjudul “[1.1.3] - 2026-10-03”- Log4Shell / JNDI detection (
log4shell_jndi): new zero-tolerance instant-block signature that detects${jndi:...}payloads in any request part (User-Agent, query string, body, headers), including the common obfuscations${${lower:j}ndi:...}and${j${lower:n}di:...}as well as URL-encoded forms such as%24%7Bjndi%3A.... Previously these payloads were neither detected nor logged, so a Log4Shell probe passed straight through.
Changed
Bagian berjudul “Changed”- README: the install command now uses the explicit stable constraint
(
composer require robyajo/laravel-security-monitor:^1.1) and warns against@dev, which forces the unreleaseddev-mainbranch instead of a tagged release.
[1.1.2] - 2026-10-02
Bagian berjudul “[1.1.2] - 2026-10-02”Changed
Bagian berjudul “Changed”- README: installation guidance refresh (explicit stable constraint and the
@devwarning).
[1.1.1] - 2026-10-02
Bagian berjudul “[1.1.1] - 2026-10-02”Changed
Bagian berjudul “Changed”- Distribution: the Astro documentation site (
web/) and thedocuments/folder are now excluded from the Composer/Packagist archive viaexport-ignoreandarchive.exclude. The previous/DOCSentry was case-sensitive and never matched the lowercasedocuments/folder, so the documentation was shipped to consumers by accident.
- Official documentation site (Astro + Starlight) maintained in a separate
repository (
robyajo/web-laravel-security). It is not part of the package distribution.
[1.1.0] - 2026-10-02
Bagian berjudul “[1.1.0] - 2026-10-02”- Livewire Starter Kit monitoring dashboard (optional): publish six
single-file Livewire pages (Overview, Security Logs, Blocked IPs, Server
Audit, User Sessions, Unblock Appeals) with
php artisan vendor:publish --tag=starterkit-livewire. The dashboard is disabled by default and served under/securitybehind theweb+auth+security.adminmiddleware. - React (Inertia) Starter Kit monitoring dashboard (optional): publish six
server-rendered Inertia + React pages and shared components with
php artisan vendor:publish --tag=starterkit-react. Backed by the newInternal\SecurityMonitor\Http\Controllers\Dashboard\*controllers, so no separate API token is required. Enable withSECURITY_DASHBOARD_DRIVER=react. --with-dashboardand--with-react-dashboardoptions onphp artisan security:install.documents/generate.php: regenerates thedocuments/index.htmlportal (Tailwind CSS Play CDN + marked.js + Mermaid.js) from the markdown chapters.
Changed
Bagian berjudul “Changed”- The
dashboardconfiguration block gained adriveroption (livewire|react) and the newSECURITY_DASHBOARD_DRIVERenvironment variable. Both starter-kit dashboards share the same route prefix and authorization middleware. - The documentation portal
documents/index.htmlnow uses the Tailwind CSS Play CDN instead of hand-written CSS, and its content is generated from the markdown chapters so it never drifts fromdocuments/.
Documentation
Bagian berjudul “Documentation”- Documented the Livewire and React dashboards in the README, the installation
guide, and the frontend integration guides, including the new
.envvariables (SECURITY_DASHBOARD_ENABLED,SECURITY_DASHBOARD_DRIVER,SECURITY_DASHBOARD_PREFIX).
[1.0.12] - 2026-10-02
Bagian berjudul “[1.0.12] - 2026-10-02”- PHP 8.2 / 8.3 compatibility (critical):
UserLoginServicechained a method call directly off anewexpression (new $model()->newQuery()). That syntax only parses from PHP 8.4, so on PHP 8.2/8.3 it raised aParseErrorthat failed every PHP 8.2/8.3 test-matrix job as well as the Pint job. It now uses$model::query(), which parses and formats identically on every supported PHP version. - PHPStan: the
view()->exists('errors.blocked')suppression now matches both thetrueandfalseevaluation, since the result depends on whether the host application has published the view.
[1.0.11] - 2026-10-02
Bagian berjudul “[1.0.11] - 2026-10-02”- CI:
laravel/pintandlarastan/larastanare no longerrequire-devdependencies. Pint requires PHP 8.3 and Larastan 3 requires Laravel 11+, which broke the PHP 8.2 / Laravel 10 matrix jobs. Both tools are now installed only in their dedicated CI jobs; runcomposer dev:toolslocally to use them. - PHPStan: replaced the environment-dependent
view()->exists()ignore with an identifier-scoped ignore forsrc/Http/Middleware/BlockIpAddress.php.
[1.0.10] - 2026-10-02
Bagian berjudul “[1.0.10] - 2026-10-02”Changed
Bagian berjudul “Changed”- The application audit now reads
PUBLIC_API_KEYandTRUSTED_PROXIESviaconfig('security.server_scan.*')instead of callingenv()inside a service, and the weak-key placeholder list no longer references an app-specific value.
- PHPStan: added
tests/*-scoped ignores for Pest’s magic$this/TestCallso IDE analysis of the test suite stays quiet, plusreportUnmatchedIgnoredErrors: false.
[1.0.9] - 2026-10-02
Bagian berjudul “[1.0.9] - 2026-10-02”- Static analysis setup: Larastan + PHPStan (
phpstan.neon.dist,phpstan-baseline.neon), acomposer analysescript, and a dedicated “Static Analysis” CI job. - Regression tests covering the CAPTCHA endpoint, login recording, session logout, trusted IP storage, admin auto-unblock, and server scan with admins.
pushMiddleware()was called on theIlluminate\Contracts\Http\Kernelinterface; middleware auto-registration now narrows to the concrete Foundation kernel before calling it.CaptchaApiControllercalled the protectedCaptchaService::render(); the public/captchaendpoint now usesgenerate()and verifies with the correct signature.- Several listeners and services referenced a non-existent
Userclass (RecordUserLogin,ResetLoginAttempts,UserLoginService::trustIp(),UserLoginService::getRealtimeActiveUsers(), andServerSecurityService::accountChecks()), which silently disabled login recording, admin auto-unblock, and the 2FA server audit. All now resolve the configured user model dynamically. - Added the missing
UserLoginService::logoutSession()method used by the admin session endpoint. - Corrected model relationship PHPDoc that referenced a non-existent
Userclass, and usedgetAuthIdentifier()where the authenticated user contract is in play.
[1.0.8] - 2026-10-02
Bagian berjudul “[1.0.8] - 2026-10-02”- Publishable default 403 page
resources/views/errors/blocked.blade.php(vendor:publish --tag=security-views), including a self-contained appeal form wired to the public unblock-ticket endpoint. Integrated intosecurity:installwith a new--without-viewsoption. - Laravel Pint configuration (
pint.json),composer format/composer lintscripts, and a dedicated “Code Style” CI job.
Changed
Bagian berjudul “Changed”- Applied Laravel Pint code style across the source and test suites.
[1.0.7] - 2026-10-02
Bagian berjudul “[1.0.7] - 2026-10-02”- Presentation deck for the package under
paparan/(Laravel-Security-Monitor-Bulwark.pptx, 20 slides) with a reproducible generator (paparan/generate.php). Excluded from the Composer distribution.
[1.0.4] - 2026-10-02
Bagian berjudul “[1.0.4] - 2026-10-02”Changed
Bagian berjudul “Changed”- Exclude development-only assets (
.agents/,AGENTS.md,DOCS/,.github/,push.sh) from the Composer distribution archive via.gitattributesexport-ignorerules and thearchive.excludeComposer setting, socomposer requireinstalls only the runtime package.
[1.0.0] - 2026-10-01
Bagian berjudul “[1.0.0] - 2026-10-01”- Self-Hosted WAF & Threat Engine:
- Zero-tolerance instant block signatures (null byte, double extensions, path traversal, webshell probes, SSTI canary, polyglot uploads).
- Multi-tier progressive threat scoring and auto-blocking with sliding time windows.
- ReDoS-hardened regex patterns tuned against real-world incidents.
- Reverse proxy support (
CF-Connecting-IP,X-Real-IP,X-Forwarded-For).
- Device-Level Quarantine & Scope:
- Granular blocking via
device_idandlocal_ip(WebRTC / device fingerprint) to avoid punishing innocent users on shared NAT/router public IPs. - Block scopes:
ip(entire router) vsdevice(specific client device).
- Granular blocking via
- Public Appeal & Ticket Submissions:
- Public headless REST API for unblock appeal ticket submission and verification.
- Admin approval/rejection endpoints with automatic IP/device quarantine release.
- Multi-Tier Stepped Login Protection:
- Stepped progressive lockouts (1m -> 5m -> 15m -> 1h -> 24h) preventing brute force and credential stuffing attacks.
- Automatic failed login security event logging.
- Zero-Dependency SVG CAPTCHA:
- Pure SVG vector-matrix challenge generator without GD or Imagick PHP extension requirements.
- Cryptographically secure one-time stateless session tokens.
- Server Integrity & Security Scanner:
- SHA-256 baseline creation and change verification.
- Suspicious file & webshell scanner with safe admin deletion capabilities (traversal protected, vital files protected).
- Server configuration audit (PHP version, debug mode, HTTPS cookies, Fortify 2FA).
- Apache / Nginx Access Log Scanner:
- Streaming log parser to detect web attacks rejected before reaching Laravel.
- Auto-import and zero-tolerance IP blocking from raw server logs.
- Headless REST API Architecture:
- 100% decoupled from any specific frontend (React/Inertia/Blade/Livewire/Mobile).
- Pure JSON endpoints for logs, blocked IPs, server scans, sessions, appeals, and captcha.
- Enterprise Extensibility:
- Configurable user model (
config('security.user_model')). - Configurable table names (
config('security.table_names.*')). HasSecurityRelationsmodel trait for seamless user relationship bindings.- Laravel 10, 11, 12, and 13 compatibility.
- Configurable user model (