Groundwork for passkey authentication, with the feature switched off by default and no behaviour change when it is off. Decision D1: passkeys require central authentication. A passkey is scoped to a relying party spanning the base domain, which only exists when SUBDOMAIN_REDIRECT is on and AUTH_SUBDOMAIN resolves to a base domain. The RP ID is therefore always that base domain, never the request host. Decision D4: HTTPS is required and is not exemptible. The allowed origin is built as https://{authSubdomain} from configuration and never from the request, so an http:// origin cannot be accepted, and isAvailableFor() additionally refuses to offer the UI on a non-secure connection. The deprecated setSecuredRelyingPartyId() escape hatch is not used and there is deliberately no override that could reintroduce one. Enabling PASSKEY_ENABLED without a usable configuration is a hard error via a non-optional cache warmer, because entrypoint.sh runs cache:warmup on every production boot: a misconfigured deployment fails to start instead of offering a button that cannot work. Also drops 12 obsolete phpstan-baseline entries for TotpTestHelper: adding #[\Override] to its anonymous clock removed the rule violation at its source rather than suppressing it. Suite: 333 tests / 770 assertions (was 313 / 738), 100% coverage on new files. phpstan level 6 clean, php-cs-fixer clean, conformance 35/35.
46 lines
1.5 KiB
PHP
46 lines
1.5 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Tests\Unit\CacheWarmer;
|
|
|
|
use App\CacheWarmer\PasskeyConfigurationWarmer;
|
|
use App\Exception\PasskeyConfigurationException;
|
|
use App\Service\PasskeyPolicyInterface;
|
|
use PHPUnit\Framework\TestCase;
|
|
|
|
/**
|
|
* The warmer is the mechanism that turns a bad passkey configuration into a
|
|
* failed deployment rather than a broken feature (D1/D4, plan §4.2).
|
|
*/
|
|
final class PasskeyConfigurationWarmerTest extends TestCase
|
|
{
|
|
public function test_it_delegates_the_configuration_check(): void
|
|
{
|
|
$policy = $this->createMock(PasskeyPolicyInterface::class);
|
|
$policy->expects(self::once())->method('assertConfigurationIsUsable');
|
|
|
|
$warmer = new PasskeyConfigurationWarmer($policy);
|
|
|
|
self::assertSame([], $warmer->warmUp('/tmp/cache'));
|
|
}
|
|
|
|
public function test_it_is_not_optional(): void
|
|
{
|
|
/* an optional warmer can be skipped, which would defeat the check */
|
|
$warmer = new PasskeyConfigurationWarmer($this->createStub(PasskeyPolicyInterface::class));
|
|
|
|
self::assertFalse($warmer->isOptional());
|
|
}
|
|
|
|
public function test_it_propagates_a_configuration_failure(): void
|
|
{
|
|
$policy = $this->createStub(PasskeyPolicyInterface::class);
|
|
$policy->method('assertConfigurationIsUsable')
|
|
->willThrowException(new PasskeyConfigurationException('nope'));
|
|
|
|
$this->expectException(PasskeyConfigurationException::class);
|
|
(new PasskeyConfigurationWarmer($policy))->warmUp('/tmp/cache');
|
|
}
|
|
}
|