New library dependency: lbuchs/webauthn (^2.2, MIT, zero transitive deps
beyond PHP+OpenSSL+Mbstring, both already required). 'none' attestation --
this only confirms "the same device that registered", not hardware
provenance, the standard trust model for a public site's own passkey login.
Backend
- migrations/010: `passkeys` (one row per registered credential: owner,
credential_id, public_key, sign_count, label) and `webauthn_challenges`
(short-lived, single-use, bridging each ceremony's "options" and "verify"
calls -- user_id set for a registration, null for a login since who's
signing in isn't known until the credential comes back).
- Config: WEBAUTHN_RP_ID (defaults to APP_URL's host) and WEBAUTHN_RP_NAME.
- PasskeyRepository, WebAuthnChallengeRepository, PasskeyController:
GET/POST /api/passkeys, POST /api/passkeys/options, DELETE
/api/passkeys/{id} (all auth), plus the public POST /api/auth/passkey/
options and /verify for login. Registration always asks for a
discoverable, user-verified credential -- what makes login usernameless:
the browser offers whatever passkeys it has for the site, no email first.
- SessionPayload now also exposes `has_passkey` on every user object
(PasskeyRepository::countForUser() > 0), reused by both the profile page
and the dismissible notice.
- PasskeyTest: auth guards, options response shape, challenge single-use/
expiry/purpose/cross-user rules, malformed-input handling, list/remove
CRUD (seeded rows) -- everything short of a real signature, which isn't
practical from PHPUnit. 73 tests pass.
Frontend
- lib/webauthn.ts: base64url <-> ArrayBuffer conversion and the two
ceremonies (registerPasskey, loginWithPasskey), matching the API's wire
format exactly.
- ProfileView: a Passkeys section -- list with Remove buttons, an "Add a
passkey" form (label pre-filled from a UA guess).
- LoginView: a "Log in with a passkey" button above the email form, shown
only when the browser supports WebAuthn.
- PasskeyNotice.vue: dismissible banner across the top of the page
(`user.has_passkey === false`); dismissal is a week-long localStorage
timestamp.
Verified against the rebuilt container using a Chrome DevTools Protocol
*virtual authenticator* (real ECDSA signing, no human interaction) end to
end: notice shown -> register a passkey -> notice gone (same page and after
navigating) -> log out -> "Log in with a passkey" with no email typed ->
correct account, notice still gone -> remove the passkey -> notice back ->
dismiss -> stays hidden for ~7 days across pages. Along the way, caught and
fixed a real bug: AuthenticatorData::getCredentialId() returns a raw binary
string, not a ByteBuffer like most of this library's other binary fields --
bin2hex() it directly rather than calling ->getHex().
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
54 lines
2.1 KiB
YAML
54 lines
2.1 KiB
YAML
name: php-project-manager
|
|
|
|
services:
|
|
app:
|
|
build: .
|
|
image: php-project-manager
|
|
ports:
|
|
- "8080:80"
|
|
environment:
|
|
APP_DEBUG: "${APP_DEBUG:-false}"
|
|
# Generated files (SQLite DB + JWT signing key) go here, on the `storage`
|
|
# volume below.
|
|
STORAGE_PATH: /var/www/storage
|
|
# Leave blank to auto-generate a secret into the storage volume on first run.
|
|
JWT_SECRET: "${JWT_SECRET:-}"
|
|
JWT_TTL: "${JWT_TTL:-86400}"
|
|
# Set to false to stop new accounts being created (existing users can
|
|
# still sign in).
|
|
APP_ALLOW_REGISTRATION: "${APP_ALLOW_REGISTRATION:-true}"
|
|
# The SPA and the API are both served from this container.
|
|
APP_URL: "${APP_URL:-http://localhost:8080}"
|
|
# Passkeys: defaults to APP_URL's host (localhost). Browsers require
|
|
# `localhost` or a real domain over HTTPS -- a LAN IP won't work.
|
|
WEBAUTHN_RP_ID: "${WEBAUTHN_RP_ID:-}"
|
|
WEBAUTHN_RP_NAME: "${WEBAUTHN_RP_NAME:-Projects}"
|
|
# Deliver to the Mailpit catcher below; read mail at http://localhost:8025.
|
|
MAIL_TRANSPORT: "${MAIL_TRANSPORT:-smtp}"
|
|
MAIL_FROM: "${MAIL_FROM:-no-reply@todo.test}"
|
|
MAIL_SMTP_HOST: "${MAIL_SMTP_HOST:-mailpit}"
|
|
MAIL_SMTP_PORT: "${MAIL_SMTP_PORT:-1025}"
|
|
MAIL_SMTP_USERNAME: "${MAIL_SMTP_USERNAME:-}"
|
|
MAIL_SMTP_PASSWORD: "${MAIL_SMTP_PASSWORD:-}"
|
|
MAIL_SMTP_ENCRYPTION: "${MAIL_SMTP_ENCRYPTION:-none}"
|
|
volumes:
|
|
# Only generated state is mounted. The app itself — PHP source and the
|
|
# built frontend — is baked into the image; rebuild to pick up changes:
|
|
# docker compose up -d --build
|
|
- storage:/var/www/storage
|
|
depends_on:
|
|
- mailpit
|
|
restart: unless-stopped
|
|
|
|
# Development mail catcher (Mailpit — the maintained MailHog successor). ~15 MB,
|
|
# single Go binary, messages held in memory. Web UI: http://localhost:8025
|
|
mailpit:
|
|
image: axllent/mailpit:v1.31
|
|
ports:
|
|
- "8025:8025" # web UI + REST API
|
|
- "1025:1025" # SMTP (also reachable in-network as mailpit:1025)
|
|
restart: unless-stopped
|
|
|
|
volumes:
|
|
storage:
|