Skip to content
LibxaFrame

News

Releases, and the engineering behind them. Mostly the bugs, because that is where the interesting part is.

Featured 8 min read

LibxaSocket 0.1.0: realtime that Laravel Echo already speaks

The package had a wire format of its own, and its own notes recorded the cost: Laravel Echo could not talk to it. It now implements the Pusher protocol on ReactPHP — the stack Reverb actually uses, which is what checking rather than assuming turned up. Plus the signature detail that fails in the worst possible way if you get it wrong.

Packages 9 min read

LibAdmin 0.2.0: the URL was a table name

The panel took the resource segment from the URL and used it directly as a table name, so any table in the database could be read, written and deleted through it, and one path interpolated it into raw SQL. Plus a plugin system where a broken plugin cannot take the panel down.

The package
Packages 7 min read

Libxa Secure 0.1.0: encryption you can actually rotate

A single encryption key makes rotation an all-or-nothing event, which is why nobody ever rotates. Secure keeps a list, so an old key goes on decrypting what it wrote while new values use the current one. Plus an audit trail and threat detection.

The package
Packages 5 min read

libxa new my-app

One command that asks which database you want, installs the skeleton, configures .env, generates the key and makes the first commit. A self-contained executable with no dependencies, because the first thing someone runs is the worst place for an install to fail.

The package
Engineering 7 min read

Your routes work locally and 404 on the server

The starter kit shipped no .htaccess, so a deployed application answered the home page and returned 404 for everything else. Three development environments each hid it for a different reason, and the one that shows it is the one you only reach after deploying.

The package
Tutorials 8 min read

Writing a LibxaFrame package

What the framework actually looks for: extra.Libxa.providers in composer.json, commands auto-discovered from src/Console/Commands, and the ServiceProvider helpers that work. Written while building two.

The package