Files
preauth/src/CacheWarmer/PasskeyConfigurationWarmer.php
T
lyra 108e9623e6 Add passkey configuration and availability policy (inert)
Groundwork for passkey authentication, with the feature switched off by
default and no behaviour change when it is off.

Decision D1: passkeys require central authentication. A passkey is scoped to
a relying party spanning the base domain, which only exists when
SUBDOMAIN_REDIRECT is on and AUTH_SUBDOMAIN resolves to a base domain. The
RP ID is therefore always that base domain, never the request host.

Decision D4: HTTPS is required and is not exemptible. The allowed origin is
built as https://{authSubdomain} from configuration and never from the
request, so an http:// origin cannot be accepted, and isAvailableFor()
additionally refuses to offer the UI on a non-secure connection. The
deprecated setSecuredRelyingPartyId() escape hatch is not used and there is
deliberately no override that could reintroduce one.

Enabling PASSKEY_ENABLED without a usable configuration is a hard error via
a non-optional cache warmer, because entrypoint.sh runs cache:warmup on every
production boot: a misconfigured deployment fails to start instead of
offering a button that cannot work.

Also drops 12 obsolete phpstan-baseline entries for TotpTestHelper: adding
#[\Override] to its anonymous clock removed the rule violation at its source
rather than suppressing it.

Suite: 333 tests / 770 assertions (was 313 / 738), 100% coverage on new
files. phpstan level 6 clean, php-cs-fixer clean, conformance 35/35.
2026-09-27 02:37:07 +00:00

53 lines
1.4 KiB
PHP

<?php
declare(strict_types=1);
namespace App\CacheWarmer;
use App\Exception\PasskeyConfigurationException;
use App\Service\PasskeyPolicyInterface;
use Override;
use Symfony\Component\HttpKernel\CacheWarmer\CacheWarmerInterface;
/**
* Fails the build (or container start) when passkeys are enabled in a
* configuration that cannot support them.
*
* `docker/entrypoint.sh` runs `cache:warmup` on every production boot with the
* real environment already injected, so a misconfiguration is caught while the
* container is starting — the deployment aborts — rather than surfacing later as
* a passkey button that silently never works.
*
* The warmer is **not** optional: an optional warmer may be skipped, which would
* let a bad configuration through.
*/
final readonly class PasskeyConfigurationWarmer implements CacheWarmerInterface
{
public function __construct(
private PasskeyPolicyInterface $passkeyPolicy,
) {
}
/**
* @return string[]
*
* @throws PasskeyConfigurationException when passkeys are enabled but unusable
*/
#[Override]
public function warmUp(string $cacheDir, ?string $buildDir = null): array
{
$this->passkeyPolicy->assertConfigurationIsUsable();
return [];
}
/**
* Never optional: skipping this warmer would defeat its entire purpose.
*/
#[Override]
public function isOptional(): bool
{
return false;
}
}