componenta / auth-webauthn
WebAuthn/passkey authentication and reauthentication for Componenta Auth 3
Requires
- php: ^8.4
- ext-json: *
- ext-openssl: *
- componenta/auth: ^3.0
- componenta/auth-session: ^1.0
- componenta/auth-session-http: ^1.0
- componenta/identity: ^1.0.1
- cycle/database: ^2.22
- psr/clock: ^1.0
- psr/http-factory: ^1.0
- psr/http-message: ^2.0
- psr/http-server-handler: ^1.0
- symfony/serializer: ^7.0|^8.0
- web-auth/webauthn-lib: ^5.3
Requires (Dev)
- componenta/clock: ^1.1.0
- nyholm/psr7: ^1.8
- phpstan/phpstan: ^2.1
- phpunit/phpunit: ^12.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-27 22:47:07 UTC
README
WebAuthn/passkey registration, authentication and reauthentication for Componenta Auth 3.
Cryptographic ceremony validation is delegated to web-auth/webauthn-lib.
Componenta owns only RP/origin configuration, short-lived one-time ceremonies,
credential persistence, identity binding, session issuance/rotation and
AuthenticationEvidence.
Discoverable browser login ceremonies are bound server-side to the exact pre-authentication transaction that requested them, preventing assertion forwarding/session-swapping across browsers.
Evidence reflects what the authenticator actually proved. A successful WebAuthn
assertion adds webauthn, possession and phishing_resistant.
user_verified is added separately only when the assertion's UV flag is set,
so privileged policy can explicitly require both phishing resistance and user
verification.
Authentication service contract
WebAuthnService::validateAuthentication() returns a
WebAuthnAuthenticationAttempt or null. After checking admission and browser
binding, call commitAuthentication(); issue or rotate a session only when it
returns true. The unused preliminary WebAuthnAuthentication DTO has been removed.