Skip to content
LibxaFrame
Packages

LibxaSocket 0.1.0: realtime that Laravel Echo already speaks

The package had a wire format of its own, and its own notes recorded the cost: Laravel Echo could not talk to it. It now implements the Pusher protocol on ReactPHP — the stack Reverb actually uses, which is what checking rather than assuming turned up. Plus the signature detail that fails in the worst possible way if you get it wrong.

8 min read

Start here

libxa new my-app

One command: it asks which database you want, installs the skeleton, configures it and makes the first commit.

Get the installer

Packages

Everything that exists, documented.

All packages

Latest

All news
Engineering 4 min read

The framework shipped an admin panel whose routes never resolved

Nova took $resourceKey in its controllers and declared {resource} in its routes, so the container could not resolve the parameter and every one of its routes raised an error instead of rendering. It also claimed /admin, which is how it was finally noticed.

Packages 9 min read

LibAdmin 0.2.0: the URL was a table name

The panel took the resource segment from the URL and used it directly as a table name, so any table in the database could be read, written and deleted through it, and one path interpolated it into raw SQL. Plus a plugin system where a broken plugin cannot take the panel down.

Packages 7 min read

Libxa Secure 0.1.0: encryption you can actually rotate

A single encryption key makes rotation an all-or-nothing event, which is why nobody ever rotates. Secure keeps a list, so an old key goes on decrypting what it wrote while new values use the current one. Plus an audit trail and threat detection.

Engineering 5 min read

A package could not ship a migration, and nothing said so

loadMigrationsFrom() was guarded by a check for a binding nothing ever created, so it silently did nothing. Every package following the documented API shipped a migration that could never run. Found by building one.

Packages 5 min read

libxa new my-app

One command that asks which database you want, installs the skeleton, configures .env, generates the key and makes the first commit. A self-contained executable with no dependencies, because the first thing someone runs is the worst place for an install to fail.