Zero-Cost Denial
Security gates requests before any module loads. Denied requests cost zero initialization and zero database queries — the cheapest possible rejection.
Security before modules. Load only what you need. Enforce isolation at runtime.
Declare a route once — it lives in data, not PHP code:
{
"routes": [
{ "method": "POST", "path": "/api/invoices", "handler": "Shop\\Http\\InvoiceController@create" }
]
}Write a controller in three lines — just orchestration:
<?php
declare(strict_types=1);
namespace App\Http;
use AlfacodeTeam\PhpServicePlatform\Kernel\Http\{Request, Response};
use App\Invoices\API\Contracts\InvoiceServiceContract;
final class InvoiceController
{
public function __construct(
private InvoiceServiceContract $invoices,
) {}
public function create(Request $request): Response
{
$dto = CreateInvoiceDTO::fromRequest($request);
$result = $this->invoices->create($dto);
return Response::json($result->toArray(), 201);
}
}The service handles transactions, domain events, and rollback. The repository speaks only to the database. The domain layer stays pure and dependency-free. The framework enforces all of this at runtime.
hkm installed and create your first project.module.json, the ModuleContract, and how modules work.