Groundwork for passkey authentication, with the feature switched off by default and no behaviour change when it is off. Decision D1: passkeys require central authentication. A passkey is scoped to a relying party spanning the base domain, which only exists when SUBDOMAIN_REDIRECT is on and AUTH_SUBDOMAIN resolves to a base domain. The RP ID is therefore always that base domain, never the request host. Decision D4: HTTPS is required and is not exemptible. The allowed origin is built as https://{authSubdomain} from configuration and never from the request, so an http:// origin cannot be accepted, and isAvailableFor() additionally refuses to offer the UI on a non-secure connection. The deprecated setSecuredRelyingPartyId() escape hatch is not used and there is deliberately no override that could reintroduce one. Enabling PASSKEY_ENABLED without a usable configuration is a hard error via a non-optional cache warmer, because entrypoint.sh runs cache:warmup on every production boot: a misconfigured deployment fails to start instead of offering a button that cannot work. Also drops 12 obsolete phpstan-baseline entries for TotpTestHelper: adding #[\Override] to its anonymous clock removed the rule violation at its source rather than suppressing it. Suite: 333 tests / 770 assertions (was 313 / 738), 100% coverage on new files. phpstan level 6 clean, php-cs-fixer clean, conformance 35/35.
86 lines
3.0 KiB
PHP
86 lines
3.0 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Service;
|
|
|
|
use App\Exception\PasskeyConfigurationException;
|
|
use Symfony\Component\HttpFoundation\Request;
|
|
|
|
/**
|
|
* Single source of truth for whether passkeys may be offered, and under which
|
|
* relying-party identity.
|
|
*
|
|
* Two project decisions are enforced here and nowhere else:
|
|
*
|
|
* - **D1 — central auth is a prerequisite.** A passkey is only meaningful when
|
|
* the whole base domain shares one relying party, so passkeys are unavailable
|
|
* unless `SUBDOMAIN_REDIRECT` is on and `AUTH_SUBDOMAIN` resolves to a base
|
|
* domain. The RP ID is therefore always that base domain.
|
|
*
|
|
* - **D4 — HTTPS is required, with no exemption.** The origin handed to the
|
|
* browser is built here as `https://{authSubdomain}` and is *never* derived
|
|
* from the incoming request, so an `http://` origin can never be accepted.
|
|
* The deprecated `setSecuredRelyingPartyId()` escape hatch is not used, and
|
|
* there is deliberately no configuration override that could reintroduce one.
|
|
*/
|
|
interface PasskeyPolicyInterface
|
|
{
|
|
/**
|
|
* True when passkeys are switched on by configuration AND that configuration
|
|
* satisfies D1. Availability to a particular visitor additionally requires
|
|
* {@see isAvailableFor()}.
|
|
*/
|
|
public function isEnabled(): bool;
|
|
|
|
/**
|
|
* Whether the passkey UI should be offered for this request.
|
|
*
|
|
* Requires the feature to be enabled, the request to be aimed at the auth
|
|
* subdomain (the only place a ceremony may run), and the visitor to actually
|
|
* be on HTTPS — see the note on scheme handling in {@see PasskeyPolicy}.
|
|
*/
|
|
public function isAvailableFor(Request $request): bool;
|
|
|
|
/**
|
|
* The relying party ID: always the base domain of the auth subdomain.
|
|
*
|
|
* @throws PasskeyConfigurationException when passkeys are enabled without D1
|
|
*/
|
|
public function rpId(): string;
|
|
|
|
/**
|
|
* Relying party origins allowed to complete a ceremony.
|
|
*
|
|
* Always exactly one entry, always `https://`, always derived from
|
|
* configuration rather than from the request (D4).
|
|
*
|
|
* @return string[]
|
|
*
|
|
* @throws PasskeyConfigurationException when passkeys are enabled without D1
|
|
*/
|
|
public function allowedOrigins(): array;
|
|
|
|
/** The auth subdomain that ceremonies must be served from. */
|
|
public function authSubdomain(): string;
|
|
|
|
/** Human-readable name shown in the authenticator prompt. */
|
|
public function rpName(): string;
|
|
|
|
/** `required`, `preferred` or `discouraged`. */
|
|
public function userVerification(): string;
|
|
|
|
/** Ceremony timeout in milliseconds, as passed to the browser. */
|
|
public function timeout(): int;
|
|
|
|
/**
|
|
* Fails hard when passkeys are enabled in a configuration that cannot work.
|
|
*
|
|
* Called during cache warm-up so a misconfigured deployment never reaches a
|
|
* browser: the container refuses to start instead.
|
|
*
|
|
* @throws PasskeyConfigurationException
|
|
*/
|
|
public function assertConfigurationIsUsable(): void;
|
|
}
|