PayloadShield SymfonyPS is a Symfony bundle that encrypts JSON responses, decrypts JSON requests, or does both using the handlers provided by ComPHPPS.
composer require payloadshield/symfonypsRegister the bundle in config/bundles.php when Symfony Flex has not registered it:
PayloadShield\SymfonyPS\PayloadShieldBundle::class => ['all' => true],Configure keys in config/packages/payload_shield.yaml:
payload_shield:
default_handler: aes-gcm-256
key: '%env(PAYLOADSHIELD_KEY)%'RSA, EC, and HPKE handlers additionally use private_key, public_key, ec_private_key, ec_public_key, hpke_private_key, and hpke_public_key. Values may be PEM contents or file paths.
Set route defaults with the PayloadShield helper:
use PayloadShield\SymfonyPS\PayloadShield;
$routes->add('secure_data', '/api/data')
->controller([DataController::class, 'show'])
->defaults(PayloadShield::encrypt('aes-gcm-256'));
$routes->add('process_data', '/api/process')
->controller([DataController::class, 'process'])
->methods(['POST'])
->defaults(PayloadShield::decrypt('aes-gcm-256'));
$routes->add('secure_process', '/api/secure-process')
->controller([DataController::class, 'process'])
->methods(['POST'])
->defaults(PayloadShield::crypt('aes-gcm-256'));The encrypted request and response envelope is {"encrypted":"..."}. The encrypted request payload must decode to a JSON object or array.
See example/README.md for a runnable app covering all eight built-in handlers.