File Vault

soarecostin/file-vault image

File Vault stats

Downloads
157.3K
Stars
177
Open Issues
22
Forks
55

View on GitHub →

File encryption / decryption in Laravel

With this package, you can encrypt and decrypt files of any size in your Laravel project. This package uses streams and CBC encryption, encrypting / decrypting a segment of data at a time.

Installation and usage

This package requires PHP 7.2 and Laravel 5.8 or higher.

You can install the package via composer:

composer require soarecostin/file-vault

Usage

Tutorials

For a detailed description of how to encrypt files in Laravel using this package, please see the following articles:

Description

This package will automatically register a facade called FileVault. The FileVault facade is using the Laravel Storage and will allow you to specify a disk, just as you would normally do when working with Laravel Storage. All file names/paths that you will have to pass into the package encrypt/decrypt functions are relative to the disk root folder. By default, the local disk is used, but you can either specify a different disk each time you call one of FileVault methods, or you can set the default disk to something else, by publishing this package's config file.

If you want to change the default disk or change the key/cipher used for encryption, you can publish the config file:

php artisan vendor:publish --provider="SoareCostin\FileVault\FileVaultServiceProvider"

This is the contents of the published file:

return [
/*
* The default key used for all file encryption / decryption
* This package will look for a FILE_VAULT_KEY in your env file
* If no FILE_VAULT_KEY is found, then it will use your Laravel APP_KEY
*/
'key' => env('FILE_VAULT_KEY', env('APP_KEY')),
 
/*
* The cipher used for encryption.
* Supported options are AES-128-CBC and AES-256-CBC
*/
'cipher' => 'AES-256-CBC',
 
/*
* The Storage disk used by default to locate your files.
*/
'disk' => 'local',
];

Encrypting a file

The encrypt method will search for a file, encrypt it and save it in the same directory, while deleting the original file.

public function encrypt(string $sourceFile, string $destFile = null, $deleteSource = true)

The encryptCopy method will search for a file, encrypt it and save it in the same directory, while preserving the original file.

public function encryptCopy(string $sourceFile, string $destFile = null)

Examples:

The following example will search for file.txt into the local disk, save the encrypted file as file.txt.enc and delete the original file.txt:

FileVault::encrypt('file.txt');

You can also specify a different disk, just as you would normally with the Laravel Storage facade:

FileVault::disk('s3')->encrypt('file.txt');

You can also specify a different name for the encrypted file by passing in a second parameter. The following example will search for file.txt into the local disk, save the encrypted file as encrypted.txt and delete the original file.txt:

FileVault::encrypt('file.txt', 'encrypted.txt');

The following examples both achive the same results as above, with the only difference that the original file is not deleted:

// save the encrypted copy to file.txt.enc
FileVault::encryptCopy('file.txt');
 
// or save the encrypted copy with a different name
FileVault::encryptCopy('file.txt', 'encrypted.txt');

Decrypting a file

The decrypt method will search for a file, decrypt it and save it in the same directory, while deleting the encrypted file.

public function decrypt(string $sourceFile, string $destFile = null, $deleteSource = true)

The decryptCopy method will search for a file, decrypt it and save it in the same directory, while preserving the encrypted file.

public function decryptCopy(string $sourceFile, string $destFile = null)

Examples:

The following example will search for file.txt.enc into the local disk, save the decrypted file as file.txt and delete the encrypted file file.txt.enc:

FileVault::decrypt('file.txt.enc');

If the file that needs to be decrypted doesn't end with the .enc extension, the decrypted file will have the .dec extention. The following example will search for encrypted.txt into the local disk, save the decrypted file as encrypted.txt.dec and delete the encrypted file encrypted.txt:

FileVault::decrypt('encrypted.txt');

As with the encryption, you can also specify a different disk, just as you would normally with the Laravel Storage facade:

FileVault::disk('s3')->decrypt('file.txt.enc');

You can also specify a different name for the decrypted file by passing in a second parameter. The following example will search for encrypted.txt into the local disk, save the decrypted file as decrypted.txt and delete the original encrypted.txt:

FileVault::decrypt('encrypted.txt', 'decrypted.txt');

The following examples both achive the same results as above, with the only difference that the original (encrypted) file is not deleted:

// save the decrypted copy to file.txt while preserving file.txt.enc
FileVault::decryptCopy('file.txt.enc');
 
// or save the decrypted copy with a different name, while preserving the file.txt.enc
FileVault::decryptCopy('file.txt.enc', 'decrypted.txt');

Streaming a decrypted file

Sometimes you will only want to allow users to download the decrypted file, but you don't need to store the actual decrypted file. For this, you can use the streamDecrypt function that will decrypt the file and will write it to the php://output stream. You can use the Laravel streamDownload method (available since 5.6) in order to generate a downloadable response:

return response()->streamDownload(function () {
FileVault::streamDecrypt('file.txt')
}, 'laravel-readme.md');

Using a different key for each file

You may need to use different keys to encrypt your files. You can explicitly specify the key used for encryption using the key method.

FileVault::key($encryptionKey)->encrypt('file.txt');

Please note that the encryption key must be 16 bytes long for the AES-128-CBC cipher and 32 bytes long for the AES-256-CBC cipher.

You can generate a key with the correct length (based on the cipher specified in the config file) by using the generateKey method:

$encryptionKey = FileVault::generateKey();

Testing

Run the tests with:

composer test

Changelog

Please see CHANGELOG for more information what has changed recently.

Contributing

Please see CONTRIBUTING for details.

Security

If you discover any security related issues, please email soarecostin@gmail.com instead of using the issue tracker.

Credits

License

The MIT License (MIT). Please see License File for more information.

Laravel Package Boilerplate

This package was generated using the Laravel Package Boilerplate.

soarecostin photo

Full-Stack Developer (Laravel/Vue) | Certified Laravel Developer

Cube

Laravel Newsletter

Join 40k+ other developers and never miss out on new tips, tutorials, and more.


Soarecostin File Vault Related Articles

Ghostty Is a Fast, Feature-Rich, Cross-Platform Terminal image

Ghostty Is a Fast, Feature-Rich, Cross-Platform Terminal

Read article
Manage Environment Variables with Eco image

Manage Environment Variables with Eco

Read article
Laravel Credentials Package for Encrypted Application Secrets image

Laravel Credentials Package for Encrypted Application Secrets

Read article
No Compromises logo

No Compromises

Joel and Aaron, the two seasoned devs from the No Compromises podcast, are now available to hire for your Laravel project. ⬧ Flat rate of $9500/mo. ⬧ No lengthy sales process. ⬧ No contracts. ⬧ 100% money back guarantee.

No Compromises
DreamzTech logo

DreamzTech

Hire 6-10+ Yrs. experienced skilled Laravel Developers from DreamzTech. We ensure NDA protected, 100% quality delivery. Contact Us & Discuss Your Need.

DreamzTech
Honeybadger logo

Honeybadger

Simple developer-focused application monitoring for Laravel. Error tracking, log management, uptime monitoring, status pages, and more!

Honeybadger
The Certification of Competence for Laravel logo

The Certification of Competence for Laravel

A community-driven, proctored assessment across 4 levels designed to validate real-world Laravel knowledge, from Junior to mastery-level Artisan. Official Vue.js, Official Nuxt, Angular, React, JS certifications also available.

The Certification of Competence for Laravel
Curotec logo

Curotec

World class Laravel experts with GenAI dev skills. LATAM-based, embedded engineers that ship fast, communicate clearly, and elevate your product. No bloat, no BS.

Curotec
PhpStorm logo

PhpStorm

The go-to PHP IDE with extensive out-of-the-box support for Laravel and its ecosystem.

PhpStorm