componenta / auth-otp
Bound one-time-code authentication challenges for Componenta Auth 3
v1.0.0
2026-09-27 22:33 UTC
Requires
- php: ^8.4
- componenta/auth: ^3.0
- componenta/auth-http: ^1.0
- componenta/auth-session: ^1.0
- componenta/auth-session-http: ^1.0
- componenta/identity: ^1.0.1
- cycle/database: ^2.22
- psr/clock: ^1.0
- psr/http-factory: ^1.0
- psr/http-message: ^2.0
- psr/http-server-handler: ^1.0
Requires (Dev)
- componenta/clock: ^1.1.0
- nyholm/psr7: ^1.8
- phpstan/phpstan: ^2.1
- phpunit/phpunit: ^12.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-27 22:46:47 UTC
README
Generic one-time-code challenges for Componenta Auth 3.
OTP is a proof mechanism, not an email-login package. Purpose and channel are bounded extensible identifiers. Browser login binds the challenge to a short-lived pre-authentication transaction; reauthentication binds it to the current public AuthSession UUID.
Security properties:
- CSPRNG 6-8 digit codes;
- HMAC-SHA-256 verifier with challenge/purpose domain separation;
- plaintext code is never persisted;
- single-use atomic verification;
- per-challenge attempt limit;
- aggregate subject+purpose failure budget survives resend/new challenge;
- resend cooldown;
- generic public invalid-code denial;
- channel-specific evidence never upgrades itself to MFA/phishing resistance.