The framework component spiral/filters
provides support for request validation, composite validation, an error message
mapping and locations, etc.
The component relies on Validation library, make sure to read it first.
The component does not require any configuration and can be activated using the bootloader Spiral\Bootloader\Security\FiltersBootloader
:
[
// ...
Spiral\\Bootloader\Security\FiltersBootloader::class
// ...
]
The filter components operate using the Spiral\Filter\InputInterface
as a primary data source:
interface InputInterface
{
public function withPrefix(string $prefix, bool $add = true): InputInterface;
public function getValue(string $source, string $name = null);
}
By default, this interface is binded to InputManager and which makes it possible to access any request's attribute using source and origin pair with dot-notation support. For example:
namespace App\Controller;
use Spiral\Filters\InputInterface;
class HomeController
{
public function index(InputInterface $input)
{
dump($input->getValue('query', 'abc')); // ?abc=1
// dot notation
dump($input->getValue('query', 'a.b.c')); // ?a[b][c]=2
// same as above
dump($input->withPrefix('a')->getValue('query', 'b.c')); // ?a[b][c]=2
}
}
Input binding is a primary way of delivering data into the filter object.
The filter object implement might vary from package to package. The default implementation provided via abstract class
Spiral\Filter\Filter
. To create custom filter to validate query:
namespace App\Filter;
use Spiral\Filters\Filter;
class MyFilter extends Filter
{
public const SCHEMA = [
'abc' => 'query:abc'
];
public const VALIDATES = [
'abc' => [
'notEmpty',
'string'
]
];
}
Or use the scaffolding
php app.php create:filter my -f "abc:string(query)"
.
You can request the Filter as method injection (it will be automatically binded to current http input):
namespace App\Controller;
use App\Filter;
class HomeController
{
public function index(Filter\MyFilter $f)
{
dump($f->isValid());
dump($f->getErrors());
dump($f->getFields());
}
}
Try URL with
?abc=1
.
Activate Spiral\Domain\FilterInterceptor
in your domain core to automatically pre-validate
your request before delivering to controller.