Files
project-manager/.env.example
T
aneurinandClaude Sonnet 5 afdd53ec4c Add passkeys (WebAuthn): register from the profile, log in without email
New library dependency: lbuchs/webauthn (^2.2, MIT, zero transitive deps
beyond PHP+OpenSSL+Mbstring, both already required). 'none' attestation --
this only confirms "the same device that registered", not hardware
provenance, the standard trust model for a public site's own passkey login.

Backend
- migrations/010: `passkeys` (one row per registered credential: owner,
  credential_id, public_key, sign_count, label) and `webauthn_challenges`
  (short-lived, single-use, bridging each ceremony's "options" and "verify"
  calls -- user_id set for a registration, null for a login since who's
  signing in isn't known until the credential comes back).
- Config: WEBAUTHN_RP_ID (defaults to APP_URL's host) and WEBAUTHN_RP_NAME.
- PasskeyRepository, WebAuthnChallengeRepository, PasskeyController:
  GET/POST /api/passkeys, POST /api/passkeys/options, DELETE
  /api/passkeys/{id} (all auth), plus the public POST /api/auth/passkey/
  options and /verify for login. Registration always asks for a
  discoverable, user-verified credential -- what makes login usernameless:
  the browser offers whatever passkeys it has for the site, no email first.
- SessionPayload now also exposes `has_passkey` on every user object
  (PasskeyRepository::countForUser() > 0), reused by both the profile page
  and the dismissible notice.
- PasskeyTest: auth guards, options response shape, challenge single-use/
  expiry/purpose/cross-user rules, malformed-input handling, list/remove
  CRUD (seeded rows) -- everything short of a real signature, which isn't
  practical from PHPUnit. 73 tests pass.

Frontend
- lib/webauthn.ts: base64url <-> ArrayBuffer conversion and the two
  ceremonies (registerPasskey, loginWithPasskey), matching the API's wire
  format exactly.
- ProfileView: a Passkeys section -- list with Remove buttons, an "Add a
  passkey" form (label pre-filled from a UA guess).
- LoginView: a "Log in with a passkey" button above the email form, shown
  only when the browser supports WebAuthn.
- PasskeyNotice.vue: dismissible banner across the top of the page
  (`user.has_passkey === false`); dismissal is a week-long localStorage
  timestamp.

Verified against the rebuilt container using a Chrome DevTools Protocol
*virtual authenticator* (real ECDSA signing, no human interaction) end to
end: notice shown -> register a passkey -> notice gone (same page and after
navigating) -> log out -> "Log in with a passkey" with no email typed ->
correct account, notice still gone -> remove the passkey -> notice back ->
dismiss -> stays hidden for ~7 days across pages. Along the way, caught and
fixed a real bug: AuthenticatorData::getCredentialId() returns a raw binary
string, not a ByteBuffer like most of this library's other binary fields --
bin2hex() it directly rather than calling ->getHex().

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 19:34:53 +01:00

53 lines
2.0 KiB
Bash

# Copy to .env and adjust as needed. All values are optional and have sane
# development defaults (see src/Support/Config.php).
# Show full exception details in API error responses. Never enable in production.
APP_DEBUG=false
# Directory for generated files: the SQLite database and the JWT signing key.
# Defaults to <project>/storage. The Docker setup points this at a volume
# outside the bind-mounted source.
STORAGE_PATH=storage
# Path to the SQLite database file (absolute, or relative to the project root).
# Defaults to <STORAGE_PATH>/database.sqlite.
DATABASE_PATH=storage/database.sqlite
# Secret used to sign JWTs. Leave blank to auto-generate one into storage/secret.key.
JWT_SECRET=
# How long an issued token stays valid, in seconds (default: 86400 = 24h).
JWT_TTL=86400
# When false, POST /api/auth/magic-link only signs existing users in -- an
# unknown address is silently ignored (same response either way) rather than
# creating a new account. Closes sign-ups without touching existing users.
APP_ALLOW_REGISTRATION=true
# Base URL the app is reached at. Verification magic links point here, e.g.
# <APP_URL>/verify-email?token=... The Docker image serves the SPA and the API
# together on http://localhost:8080; a host `npm run dev` serves it on :5173.
APP_URL=http://localhost:8080
# WebAuthn (passkeys). The relying party ID is the domain a passkey is bound
# to -- defaults to APP_URL's host. Browsers only allow `localhost` or a real
# domain served over HTTPS, so passkeys won't work when APP_URL is a LAN IP.
WEBAUTHN_RP_ID=
WEBAUTHN_RP_NAME=Projects
# Email delivery.
# mail — PHP's built-in mail() function (default)
# smtp — the SMTP server configured below
# log — append messages to MAIL_LOG_PATH instead of sending (dev/test)
MAIL_TRANSPORT=mail
MAIL_FROM=no-reply@todo.test
MAIL_FROM_NAME=Projects
MAIL_LOG_PATH=storage/mail.log
# Only used when MAIL_TRANSPORT=smtp.
MAIL_SMTP_HOST=
MAIL_SMTP_PORT=587
MAIL_SMTP_USERNAME=
MAIL_SMTP_PASSWORD=
MAIL_SMTP_ENCRYPTION=tls # tls | ssl | none