Ibexa 4 PHP Firewall
per Carles Mateo
DoS
Firewall
Ibexa
OSS
Security
PHP Firewall for Ibexa covers every 4.6.x release (LTS) and every edition - OSS, Headless, Experience, Commerce - because it only uses packages included in the OSS edition (core kernel, Admin UI, Doctrine DBAL, Symfony).
PHP Firewall hooks into Symfony's request handling at the very start, before Ibexa routes the request. So every request that reaches PHP passes through it, whichever Ibexa edition or bundle would then handle it.
This way is able to cut abusive requests at a very early stage, avoiding overload in the server.
It is installed from the zip via a composer path repository + config/bundles.php (no automatic updates).
It provides the functionality from the popular PHP Firewall for Drupal, WordPress, and PrestaShop, plus specific protection for too many POSTs to /login /admin/login or /api/ibexa/v2/users/sessions and a separate rate limit for POST /graphql, which is attractive for scrapping and abuse.
Its code is based on well tested Symfony 5 code from PHP Firewall for Drupal module.
Its unique WAF and rate-limiter features protects from DoS and from bots consuming resources from origin.
This license is for for server, yearly, and covers up to 5 domains served from the same server.