Cloee Docs
Paymenter ExtensionsSafeGuard

CLI Reference

Account Protection registers several artisan commands under the account-protection namespace. These are useful for emergency egress (e.g., when staff IPs are bl

Account Protection registers several artisan commands under the account-protection namespace. These are useful for emergency egress (e.g., when staff IPs are blocked) or for scripting changes.

Run php artisan list account-protection to view all commands.

IP Whitelist Commands

Add

# Single IP
php artisan account-protection:ip-whitelist:add 203.0.113.5 \
  --notes="Finance office" \
  --no-registration       # optional flags disable specific bypasses

# CIDR range
php artisan account-protection:ip-whitelist:add 173.245.48.0/20 \
  --notes="Cloudflare IPv4"

Flags available:

  • --notes= – store additional context
  • --no-registration – do not bypass registration limit
  • --no-vpn / --no-proxy / --no-tor / --no-relay

Remove

php artisan account-protection:ip-whitelist:remove 203.0.113.5

List

php artisan account-protection:ip-whitelist:list

Shows all whitelist entries and their bypass flags.

Clear

php artisan account-protection:ip-whitelist:clear
# add --force to skip confirmation

Export

php artisan account-protection:ip-whitelist:export storage/app/ip-whitelist.json
# --format=csv to export as CSV (default is json)
# --force overwrites existing files

If you omit the path, the command writes to storage/app/account_protection_ip_whitelist_<timestamp>.<ext>.

Import

php artisan account-protection:ip-whitelist:import storage/app/ip-whitelist.json \
  --format=json \
  --replace \
  --force
  • --format= is optional when the extension (.json/.csv) matches the payload.
  • --replace wipes the current whitelist before importing (prompted unless --force is present).
  • The command reports Created/Updated/Skipped counts so you can audit the load.

File Layout

JSON expects an array of objects:

[
  {
    "ip_address": "203.0.113.10",
    "notes": "Finance office",
    "bypass_registration": true,
    "bypass_vpn": true,
    "bypass_proxy": false,
    "bypass_tor": false,
    "bypass_relay": true
  }
]

CSV requires these lowercase headers (1/0, true/false, yes/no all map to booleans):

ip_address,notes,bypass_registration,bypass_vpn,bypass_proxy,bypass_tor,bypass_relay
203.0.113.10,Finance office,1,1,0,0,1

Account Whitelist Commands

Whitelist specific user accounts to bypass VPN/proxy detection. Useful for staff or VIP customers who may use VPNs legitimately.

Add

# By email
php artisan account-protection:account-whitelist:add [email protected] \
  --notes="VIP customer"

# By user ID
php artisan account-protection:account-whitelist:add 42 \
  --notes="Staff member" \
  --no-vpn                # optional flags disable specific bypasses

Flags available:

  • --notes= – store additional context
  • --no-vpn / --no-proxy / --no-tor / --no-relay

Remove

php artisan account-protection:account-whitelist:remove [email protected]
# or by ID
php artisan account-protection:account-whitelist:remove 42

List

php artisan account-protection:account-whitelist:list

Shows all whitelisted accounts with their bypass flags.

Clear

php artisan account-protection:account-whitelist:clear
# add --force to skip confirmation

IP Ban Commands

Add a Ban

php artisan account-protection:ip-ban:add 198.51.100.9 \
  --reason="Chargeback fraud" \
  --minutes=1440          # optional expiry in minutes

Release a Ban

php artisan account-protection:ip-ban:release 198.51.100.9 \
  --notes="Verified customer"

List Bans

php artisan account-protection:ip-ban:list
php artisan account-protection:ip-ban:list --active   # only active bans

IP Log Commands

List Recent Entries

php artisan account-protection:ip-log:list --limit=50
php artisan account-protection:ip-log:list [email protected]

Shows recorded login/registration IPs, timestamps, and user agents.

Email Blocklist Commands

Sync Disposable Domains

php artisan account-protection:email-blocklist:sync
# add --force to ignore the configured sync interval

The command downloads the disposable domain list (default GitHub source), upserts entries, applies the grace-period removal policy, and prints:

  • Total domains fetched and the source URL
  • Added / updated / removed counts
  • Pending removal count (domains that went missing but are still inside the grace window)
  • A short sample of domains so you can confirm the payload

Use it inside cron or external automation. The extension also registers the command with Laravel’s scheduler when auto-sync is enabled.

Usage Tips

  • Pair these commands with cronjobs or monitoring to export data regularly.
  • All commands return non-zero exit codes when the requested action fails, allowing use inside scripts.
  • When automating via CI/Ansible, run them from the Paymenter root (same directory as artisan).

Troubleshooting

  • If commands are missing, confirm the extension is enabled and the application is running in console mode (no cached config disabling the service provider).
  • Command errors are written to storage/logs/. Use tail -f during execution to watch output live.

These tools provide a safety net when the admin UI is inaccessible or when swift action is required.


On this page