Cloee Docs
Paymenter ExtensionsSafeGuard

Usage

Add entries to the IP Whitelist page (or via CLI) to bypass specific checks:

Registration Safeguards

  • If a name scores below the configured threshold, the user receives a localized validation error.
  • When max accounts per IP is set, the extension checks the historical IP log and blocks the signup after the limit.
  • When vpnapi.io integration is enabled, IPs flagged as VPN/Proxy/Tor/Relay are auto-banned (subject to whitelist) and the request is aborted.
  • Passwords are checked against the configurable policy (length / uppercase / lowercase / number / symbol); violations surface as field errors.

Whitelisting During Registration

Add entries to the IP Whitelist page (or via CLI) to bypass specific checks:

  • Bypass Registration allows more than the configured per-IP limit.
  • Bypass VPN/Proxy/Tor/Relay ignores reputation results for that IP.

Account Suspensions

Navigate to Account Protection → Account Suspensions to create or manage suspensions.

  1. Choose a user.
  2. Select Temporary or Permanent.
  3. Optionally set an “Ends At” timestamp for temporary suspensions.
  4. Toggle Block IP address to also ban the user’s most recent IP. Provide a custom IP to block or leave blank to use their latest recorded address.
  5. Toggle Send suspension email if you want to notify the customer immediately. Uncheck for silent suspensions.
  6. Add reasoning; submit.

Suspending a user immediately removes active sessions, optionally creates an IP ban, and can trigger an email/webhook if enabled. Releases lift the suspension and notify webhooks; admins can choose to email the customer when lifting the ban.

Bulk Imports & Exports

Use the header actions on Account Protection → IP Whitelist:

  • Export opens a dialog to choose JSON (default) or CSV and streams the file to your browser.
  • Import accepts JSON or CSV uploads, with an optional Replace existing entries toggle. When enabled, the current whitelist is cleared before new rows are applied.

Accepted payload formats mirror the CLI tools:

[
  {
    "ip_address": "203.0.113.10",
    "notes": "Finance office",
    "bypass_registration": true,
    "bypass_vpn": true,
    "bypass_proxy": false,
    "bypass_tor": false,
    "bypass_relay": true
  }
]
ip_address,notes,bypass_registration,bypass_vpn,bypass_proxy,bypass_tor,bypass_relay
203.0.113.10,Finance office,1,1,0,0,1

Boolean fields accept true/false, yes/no, or 1/0. Invalid or missing ip_address rows are skipped and reported in the success toast.

IP Bans

The IP Bans page lists manual and automatic bans. From here you can:

  • Review the ban reason, expiration, and current status.
  • Release a ban (with optional notes) via the action button.
  • Delete an entry completely if necessary.

Login Fail2Ban

Account Protection counts failed login attempts per email + IP/fingerprint. Once a user exceeds the configured threshold within the rolling window, the extension temporarily bans that identity.

  • Configure the strike limit, window, and ban duration under Extensions → Account Protection Settings (Login Fail2Ban, Max Failed Logins, Failed Attempt Window, Ban Duration).
  • The guard is bypassed for IPs/accounts in the whitelists (including the new Ignore Login Throttle flag).
  • Suspicious attempts and active bans surface under Account Protection → Login Attempts / Login Bans. Admins can lift bans or inspect individual attempts from these Filament resources.
  • A manual Sync Disposable List button is available on the Login Bans page to refresh data used by the lockout notifications.

Tips

  • Use the CLI account-protection:email-blocklist:sync command (documented below) after adjusting thresholds to ensure disposable domains are blocked before attack campaigns start.
  • Pair the throttling with webhook alerts or monitoring to notify your team when bans spike.

IP & Account Whitelists

  • IP Whitelist – bypasses limits for specific IP addresses. Each entry can independently opt out of registration limits and VPN/Proxy/Tor/Relay checks.
  • Account Whitelist – lets you mark trusted customer accounts, overriding the same checks even if their IP changes. Helpful for staff accounts or known partners.

Email Blocklist

Account Protection ships with a managed email domain blocklist covering disposable providers. You can blend the upstream list with your own entries.

Managing Entries

  • Navigate to Account Protection → Email Blocklist to add, edit, or delete domains or specific addresses.
  • The list shows the Source (manual vs. remote) and Synced timestamp so you know when entries last refreshed.
  • Use the header actions:
    • Add Entry – creates a manual deny entry.
    • Sync Disposable List – forces an immediate download from the configured source and reports counts (Added/Updated/Removed/Pending).

Automatic Sync

  • Enable Auto Sync Disposable List and set the interval in minutes from the extension settings. The scheduler will run the sync command automatically (and the service skips if the interval hasn’t elapsed).
  • The importer keeps a grace window (default 3 days) before removing domains that disappear upstream to avoid occasional blips wiping your list.

CLI

See the new command in the CLI Reference for scripted syncs or cron jobs.

User IP Logs

Provides an audit trail of login and registration IPs:

  • Useful for forensic research or manual suspensions.
  • Works with CLI commands to export or filter logs.

Webhooks

When enabled, Account Protection posts JSON/Discord-style messages for:

  • IP bans (automatic or manual)
  • IP releases
  • User suspensions
  • Suspension releases

Discord webhooks are fully supported; other endpoints receive a compact JSON payload. Failed deliveries are logged to storage/logs/laravel-YYYY-MM-DD.log.

Error Handling

  • Validation exceptions surface to end users with clear messages.
  • IP reputation failures fall back to cached results and log warnings (no blocking by default).
  • CLI commands exit with non-zero status codes if actions could not be completed (e.g., removing a non-existent whitelist entry).

Monitor storage/logs/ for actionable messages, and use the CLI tools for recovery when UI access is limited.


On this page