- Add .dockerignore to exclude .git, vendor, var, tests, docs, .env
and other non-build files from Docker context
- Fix broken base64url padding in src/Data/Payload.php: str_pad was
a no-op because the length argument was always < string length.
Replaced with correct str_repeat approach
- Fix typo in bin/franken.sh: digtialadapt → digitaladapt
- Add comment to bin/franken.sh noting it's a dev utility
- Remove config/reference.php from git tracking (auto-generated file)
and add to .gitignore
- Fix readme.md: env.example → example.env (matches actual filename)
- Add TestKernel that removes the kernel.reset tag from nonceCache,
rateLimitCache, sessionCache and sessionStorage pools so in-memory
state survives across requests within a single test (mirroring APCu
persistence in production)
- Add config/packages/test/ with array cache adapters and test session
config
- Set fixed TOTP secret (JBSWY3DPEHPK3PXP) and high rate limits in
phpunit.dist.xml and .env.test so functional tests can compute valid
codes and are not rate-limited
- Make Kernel non-final so TestKernel can extend it
- Fix testFailedLoginWithSpentNonceIsRejected and
testConsumedBackupCodeCannotBeReused: clear the CookieJar between
sub-requests so a session cookie set by a prior successful login does
not auto-authenticate the next request via AcceptListener before the
nonce/backup-code path is exercised
Intending to build support for single-use backup codes.
Started refactoring to move trait dependencies internally, so that classes only have to specify their own direct dependencies.