componenta / auth-totp
Encrypted TOTP enrollment and reauthentication for Componenta Auth 3
v1.0.0
2026-09-27 22:33 UTC
Requires
- php: ^8.4
- ext-sodium: *
- componenta/auth: ^3.0
- componenta/auth-session: ^1.0
- componenta/auth-session-http: ^1.0
- componenta/identity: ^1.0.1
- cycle/database: ^2.22
- psr/clock: ^1.0
- psr/http-factory: ^1.0
- psr/http-message: ^2.0
- psr/http-server-handler: ^1.0
- spomky-labs/otphp: ^11.5
Requires (Dev)
- componenta/clock: ^1.1.0
- nyholm/psr7: ^1.8
- phpstan/phpstan: ^2.1
- phpunit/phpunit: ^12.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-27 22:47:03 UTC
README
Encrypted TOTP enrollment and reauthentication for Componenta Auth 3.
The package uses spomky-labs/otphp for RFC 6238 verification and libsodium
XChaCha20-Poly1305 for secret encryption at rest.
Security properties:
- raw TOTP secrets are returned only during enrollment and are never stored;
- database rows contain authenticated ciphertext + nonce + key id;
- accepted time steps are persisted and cannot be replayed;
- enrollment must be confirmed with a valid code before the credential becomes active;
- pending enrollment secrets expire after a bounded server-side TTL (10 minutes by default);
- TOTP evidence adds a possession factor but never claims phishing resistance;
- successful reauthentication rotates the active
SessionCredential.