componenta / auth-magic-link
Pre-auth-bound magic-link authentication for Componenta Auth 3
Requires
- php: ^8.4
- componenta/auth: ^3.0
- componenta/auth-http: ^1.0
- componenta/auth-session: ^1.0
- componenta/auth-session-http: ^1.0
- componenta/auth-token: ^1.0
- componenta/identity: ^1.0.1
- psr/http-factory: ^1.0
- psr/http-message: ^2.0
- psr/http-server-handler: ^1.0
Requires (Dev)
- nyholm/psr7: ^1.8
- phpstan/phpstan: ^2.1
- phpunit/phpunit: ^12.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-27 22:46:43 UTC
README
Magic-link authentication for Componenta Auth 3.
The default browser profile is same-browser only. Requesting a link creates a
short-lived pre-authentication transaction. The delivery adapter must put both
the opaque one-time token and the public pre-auth transaction UUID (binding)
into the link.
The landing page POSTs both values to the verify endpoint while the browser also presents the HttpOnly pre-auth cookie and memory-held request token. The binding UUID must match that exact browser transaction before the one-time token is consumed. This prevents login-CSRF/session-swapping and intentionally does not model cross-device magic links.
One-time bearer persistence is delegated to componenta/auth-token.
Magic-link evidence is intentionally classified as one_time_link, not as a
generic possession factor and not as phishing resistant. In particular, an
email-delivered link must not accidentally satisfy an assurance policy that
expects a cryptographic possession authenticator.