Giter Club home page Giter Club logo

laravel-database-model-encryption's Introduction

Laravel DB Encryption Package

Package for encrypting and decrypting model attributes for Laravel using Laravel's Crypt

Most of client wanted to encrypt their database. So encase a person got access to database, they won't see the actual data of it. BUT the problem is, developers will have difficulty searching encrypted data when they need it.

The purpose of this project is to create a set-it-and-forget-it package that can be installed without much effort to encrypt and decrypt Eloquent model attributes stored in your database tables, and most of all able to search encrypted database fields using whereEncrypted and orWhereEncrypted functions similar to laravel eloquent's where and orWhere.

Key Features

  • Encrypt, Decrypt database fields easily
  • Minimal configuration
  • Include searching encrypted data using the following: whereEncrypted and orWhereEncrypted
  • uses Laravel's Facades Crypt for encrypting and decrypting fields

Requirements

  • Laravel: 5.5, 5.6, 5.7, or 5.8
  • PHP: 5.6 Above

Schema Requirements

Encrypted values are usually longer than plain text values, sometimes much longer. You may find that the column widths in your database tables need to be altered to store the encrypted values generated by this package.

We highly recommend to alter your column types to TEXT or LONGTEXT

Installation

Step 1: Composer

Via Composer command line:

$ composer require dustapplication/laravel-database-model-encryption

Step 2: Add ServiceProvider to your app/config.php file (Laravel 5.4 or below)

Add the service provider to the providers array in the config/app.php config file as follows:

    'providers' => [
        ...
        \DustApplication\Encryption\Providers\EncryptServiceProvider::class,
    ],

Usage

Use the EncryptedAttribute trait in any Eloquent model that you wish to apply encryption to and define a protected $encrypted array containing a list of the attributes to encrypt.

For example:

    
    use DustApplication\Encryption\Traits\EncryptedAttribute;

    class User extends Eloquent {
        use EncryptedAttribute;
       
        /**
         * The attributes that should be encrypted on save.
         *
         * @var array
         */
        protected $encryptable = [
            'first_name', 'last_name'
        ];
    }

By including the EncryptedAttribute trait, the setAttribute(), getAttribute() and getAttributeFromArray() methods provided by Eloquent are overridden to include an additional step.

Searching Encrypted Fields Example:

Searching encrypted field can be done by calling the whereEncrypted and orWhereEncrypted functions similar to laravel eloquent where and orWhere.

    namespace App\Http\Controllers;

    use App\User;
    class UsersController extends Controller {
        public function index(Request $request)
        {
            $user = User::whereEncrypted('first_name','john')
                        ->orWhereEncrypted('last_name','!=','Doe')->firstOrFail();
            
            return $user;
        }
    }

NOTE:

The use of encryption searching is recommended for small group of data. Using it on large amount of data rows will affects the performance.

Encrypt your current data

If you have current data in your database you can encrypt it with the: php artisan encryptable:encryptModel 'App\User' command.

Additionally you can decrypt it using the: php artisan encryptable:decryptModel 'App\User' command.

Note: You must implement first the Encryptable trait and set $encryptable attributes

Exists and Unique Validation Rules

If you are using exists and unique rules with encrypted values replace it with exists_encrypted and unique_encrypted php $validator = validator(['email'=>'[email protected]'], ['email'=>'exists_encrypted:users,email']); $validator = validator(['email'=>'[email protected]'], ['email'=>'unique_encrypted:users,email']);

Frequently Asked Question

Can I use other encryption other than crypt?

No for now, but we may include it on next update

Can I search encrypted data?

YES! You will able to search on attributes which are encrypted by this package because. If you need to search on data then use the whereEncrypted and orWhereEncrypted function:

    User::whereEncrypted('email','[email protected]')->orWhereEncrypted('email','[email protected]')->firstOrFail();

It will automatically added on the eloquent once the model uses EncryptedAttribute

Can I encrypt all my User model data?

Aside from IDs you can encrypt everything you wan't

For example: Logging-in on encrypted email

$user = User::whereEncrypted('email','[email protected]')->filter(function ($item) use ($request) {
        return Hash::check($password, $item->password);
    })->where('active',1)->first();

Credits

This package was inspired from the following: austinheap/laravel-database-encryption magros/laravel-model-encryption

License

The MIT License (MIT). Please see License File for more information.

laravel-database-model-encryption's People

Contributors

dustapplication avatar vincentkristoffer avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.