Groundwork for passkey authentication, with the feature switched off by default and no behaviour change when it is off. Decision D1: passkeys require central authentication. A passkey is scoped to a relying party spanning the base domain, which only exists when SUBDOMAIN_REDIRECT is on and AUTH_SUBDOMAIN resolves to a base domain. The RP ID is therefore always that base domain, never the request host. Decision D4: HTTPS is required and is not exemptible. The allowed origin is built as https://{authSubdomain} from configuration and never from the request, so an http:// origin cannot be accepted, and isAvailableFor() additionally refuses to offer the UI on a non-secure connection. The deprecated setSecuredRelyingPartyId() escape hatch is not used and there is deliberately no override that could reintroduce one. Enabling PASSKEY_ENABLED without a usable configuration is a hard error via a non-optional cache warmer, because entrypoint.sh runs cache:warmup on every production boot: a misconfigured deployment fails to start instead of offering a button that cannot work. Also drops 12 obsolete phpstan-baseline entries for TotpTestHelper: adding #[\Override] to its anonymous clock removed the rule violation at its source rather than suppressing it. Suite: 333 tests / 770 assertions (was 313 / 738), 100% coverage on new files. phpstan level 6 clean, php-cs-fixer clean, conformance 35/35.
53 lines
1.4 KiB
PHP
53 lines
1.4 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\CacheWarmer;
|
|
|
|
use App\Exception\PasskeyConfigurationException;
|
|
use App\Service\PasskeyPolicyInterface;
|
|
use Override;
|
|
use Symfony\Component\HttpKernel\CacheWarmer\CacheWarmerInterface;
|
|
|
|
/**
|
|
* Fails the build (or container start) when passkeys are enabled in a
|
|
* configuration that cannot support them.
|
|
*
|
|
* `docker/entrypoint.sh` runs `cache:warmup` on every production boot with the
|
|
* real environment already injected, so a misconfiguration is caught while the
|
|
* container is starting — the deployment aborts — rather than surfacing later as
|
|
* a passkey button that silently never works.
|
|
*
|
|
* The warmer is **not** optional: an optional warmer may be skipped, which would
|
|
* let a bad configuration through.
|
|
*/
|
|
final readonly class PasskeyConfigurationWarmer implements CacheWarmerInterface
|
|
{
|
|
public function __construct(
|
|
private PasskeyPolicyInterface $passkeyPolicy,
|
|
) {
|
|
}
|
|
|
|
/**
|
|
* @return string[]
|
|
*
|
|
* @throws PasskeyConfigurationException when passkeys are enabled but unusable
|
|
*/
|
|
#[Override]
|
|
public function warmUp(string $cacheDir, ?string $buildDir = null): array
|
|
{
|
|
$this->passkeyPolicy->assertConfigurationIsUsable();
|
|
|
|
return [];
|
|
}
|
|
|
|
/**
|
|
* Never optional: skipping this warmer would defeat its entire purpose.
|
|
*/
|
|
#[Override]
|
|
public function isOptional(): bool
|
|
{
|
|
return false;
|
|
}
|
|
}
|