Groundwork for passkey authentication, with the feature switched off by default and no behaviour change when it is off. Decision D1: passkeys require central authentication. A passkey is scoped to a relying party spanning the base domain, which only exists when SUBDOMAIN_REDIRECT is on and AUTH_SUBDOMAIN resolves to a base domain. The RP ID is therefore always that base domain, never the request host. Decision D4: HTTPS is required and is not exemptible. The allowed origin is built as https://{authSubdomain} from configuration and never from the request, so an http:// origin cannot be accepted, and isAvailableFor() additionally refuses to offer the UI on a non-secure connection. The deprecated setSecuredRelyingPartyId() escape hatch is not used and there is deliberately no override that could reintroduce one. Enabling PASSKEY_ENABLED without a usable configuration is a hard error via a non-optional cache warmer, because entrypoint.sh runs cache:warmup on every production boot: a misconfigured deployment fails to start instead of offering a button that cannot work. Also drops 12 obsolete phpstan-baseline entries for TotpTestHelper: adding #[\Override] to its anonymous clock removed the rule violation at its source rather than suppressing it. Suite: 333 tests / 770 assertions (was 313 / 738), 100% coverage on new files. phpstan level 6 clean, php-cs-fixer clean, conformance 35/35.
25 lines
1018 B
YAML
25 lines
1018 B
YAML
twig:
|
|
file_name_pattern: '*.twig'
|
|
strict_variables: true
|
|
globals:
|
|
env:
|
|
title: '%env(TITLE)%'
|
|
bg_color: '%env(BG_COLOR)%'
|
|
fg_color: '%env(FG_COLOR)%'
|
|
error_color: '%env(ERROR_COLOR)%'
|
|
id_name: '%env(ID_NAME)%'
|
|
token_name: '%env(TOKEN_NAME)%'
|
|
submit_name: '%env(SUBMIT_NAME)%'
|
|
error_message: '%env(ERROR_MESSAGE)%'
|
|
teapot_title: '%env(TEAPOT_TITLE)%'
|
|
teapot_message: '%env(TEAPOT_MESSAGE)%'
|
|
too_many_title: '%env(TOO_MANY_TITLE)%'
|
|
too_many_message: '%env(TOO_MANY_MESSAGE)%'
|
|
passkey_button_name: '%env(PASSKEY_BUTTON_NAME)%'
|
|
passkey_register_name: '%env(PASSKEY_REGISTER_NAME)%'
|
|
debug: '%env(SHELL_VERBOSITY)%'
|
|
|
|
# `passkeys` is computed per request by the controller-facing templates via
|
|
# PasskeyPolicyInterface, never from an env var, so that availability and the
|
|
# D1/D4 prerequisites cannot drift apart.
|