Files
preauth/tests/Unit/CacheWarmer/PasskeyConfigurationWarmerTest.php
T
lyra 108e9623e6 Add passkey configuration and availability policy (inert)
Groundwork for passkey authentication, with the feature switched off by
default and no behaviour change when it is off.

Decision D1: passkeys require central authentication. A passkey is scoped to
a relying party spanning the base domain, which only exists when
SUBDOMAIN_REDIRECT is on and AUTH_SUBDOMAIN resolves to a base domain. The
RP ID is therefore always that base domain, never the request host.

Decision D4: HTTPS is required and is not exemptible. The allowed origin is
built as https://{authSubdomain} from configuration and never from the
request, so an http:// origin cannot be accepted, and isAvailableFor()
additionally refuses to offer the UI on a non-secure connection. The
deprecated setSecuredRelyingPartyId() escape hatch is not used and there is
deliberately no override that could reintroduce one.

Enabling PASSKEY_ENABLED without a usable configuration is a hard error via
a non-optional cache warmer, because entrypoint.sh runs cache:warmup on every
production boot: a misconfigured deployment fails to start instead of
offering a button that cannot work.

Also drops 12 obsolete phpstan-baseline entries for TotpTestHelper: adding
#[\Override] to its anonymous clock removed the rule violation at its source
rather than suppressing it.

Suite: 333 tests / 770 assertions (was 313 / 738), 100% coverage on new
files. phpstan level 6 clean, php-cs-fixer clean, conformance 35/35.
2026-09-27 02:37:07 +00:00

46 lines
1.5 KiB
PHP

<?php
declare(strict_types=1);
namespace App\Tests\Unit\CacheWarmer;
use App\CacheWarmer\PasskeyConfigurationWarmer;
use App\Exception\PasskeyConfigurationException;
use App\Service\PasskeyPolicyInterface;
use PHPUnit\Framework\TestCase;
/**
* The warmer is the mechanism that turns a bad passkey configuration into a
* failed deployment rather than a broken feature (D1/D4, plan §4.2).
*/
final class PasskeyConfigurationWarmerTest extends TestCase
{
public function test_it_delegates_the_configuration_check(): void
{
$policy = $this->createMock(PasskeyPolicyInterface::class);
$policy->expects(self::once())->method('assertConfigurationIsUsable');
$warmer = new PasskeyConfigurationWarmer($policy);
self::assertSame([], $warmer->warmUp('/tmp/cache'));
}
public function test_it_is_not_optional(): void
{
/* an optional warmer can be skipped, which would defeat the check */
$warmer = new PasskeyConfigurationWarmer($this->createStub(PasskeyPolicyInterface::class));
self::assertFalse($warmer->isOptional());
}
public function test_it_propagates_a_configuration_failure(): void
{
$policy = $this->createStub(PasskeyPolicyInterface::class);
$policy->method('assertConfigurationIsUsable')
->willThrowException(new PasskeyConfigurationException('nope'));
$this->expectException(PasskeyConfigurationException::class);
(new PasskeyConfigurationWarmer($policy))->warmUp('/tmp/cache');
}
}