NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #271 most downloaded on Packagist
FIDO2/Webauthn Support For PHP
Last release 27 days ago
10 Sep 2026
Ships unpredictably
gaps range from 1 weeks to 9 months
Rarely documented
notes for 13 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
126 releases · first in 2019
BREAKING CHANGE: webauthn.cose.algorithm.ED256 and webauthn.cose.algorithm.ED512 are no longer registered, so the default verification manager no long…
Both dependencies published security advisories. Raising the constraints
guarantees users get the patched releases instead of relying on Composer
picking a recent enough version.
cose-lib 4.8.0 now enforces X.690 section 8.1.3 when parsing an ECDSA
signature: the SEQUENCE length octets must cover exactly the contents
octets. The ES512 left-padding fixture declared 134 content octets while
carrying 135, so it is rejected as malformed. The fixture is corrected to
0x87, the length it always should have had.
Ed256 (-260) and Ed512 (-261) sign a SHA-256 or SHA-512 digest of the payload
with pure Ed25519, a construction no specification defines. IANA assigned both
identifiers to unrelated algorithms, WalnutDSA and TurboSHAKE128.
As of 4.8.0, web-auth/cose-lib emits an E_USER_WARNING when either algorithm is
built without an explicit acknowledgement, and the Symfony error handler turns
that warning into an exception in the dev environment, so every attestation or
assertion request answers with a 500 as soon as the algorithm manager is built.
This is the same failure RS1 caused, with the same resolution: the bundle does
not acknowledge a questionable algorithm on behalf of the applications, so the
definitions are removed instead.
BREAKING CHANGE: webauthn.cose.algorithm.ED256 and webauthn.cose.algorithm.ED512
are no longer registered, so the default verification manager no longer accepts
their signatures. The bundle never offered them at the registration, since
public_key_credential_parameters defaults to an empty list, so only the
applications that explicitly added -260 or -261 to that list are affected. They
have to declare the services themselves; autoconfiguration adds them back to the
manager.
One column per quarter.
fix(rp-entity): default rp.name to the Relying Party ID when serializ…
fix(rp-entity): default rp.name to the Relying Party ID when serializ…
fix(rp-entity): default rp.name to the Relying Party ID when serializ…
fix(rp-entity): default rp.name to the Relying Party ID when serializ…
fix(authenticator-data): restrict FLAG_RFU2 to bit 5
Bits 3 and 4 were reserved in Webauthn Level 2 and have been assigned to
BE (Backup Eligibility) and BS (Backup State) in Level 3. The mask was
never narrowed, so getReservedForFutureUse2() reported the backup flags
a second time: a synced passkey with BE and BS set returned 24 instead
of 0.
Closes #920
The specification requires the keys of the evalByCredential map to be
the base64url encoding of the credential ID, and the client rejects the
ceremony with a SyntaxError otherwise. The builder encoded the salts but
used the credential ID as given, which made a raw credential ID produce
an invalid key.
Closes #924
tokenBinding is [RESERVED] since Webauthn Level 3. The value was never
read nor exposed, so the only effect of the check was to fail a ceremony
over a member the Relying Party does not use, with a truncated error
message. The raw client data remains available through the data
property.
Closes #929
The ASN.1 DER encoding of an ECDSA signature has a variable length, as
w3c/webauthn#2315 now makes explicit in the specification example. The
class handling the conversion had no test at all.
Closes #930
fix(fake-credentials): deprecate SimpleFakeCredentialGenerator without a secret ( GHSA-gq4g-fpc9-vjfq )
With an empty secret the decoy credentials derive only from the username
and become predictable, letting an unauthenticated requester tell fake
responses from real ones and re-enabling username enumeration. Emit a
deprecation when the generator is built without a secret; a non-empty
secret will be required in 6.0.0. The Symfony bundle already injects
kernel.secret, so default deployments are unaffected.
Validates the fix and guards against regressions:
fix(top-origin): reject cross-origin responses when no validator is c…
fix(top-origin): reject cross-origin responses when no validator is c…
fix(origins): accept non-URL facet IDs (e.g. android:apk-key-hash:...…
fix(origins): accept non-URL facet IDs (e.g. android:apk-key-hash:...…
feat: support Conditional Create (mediation) for auto-register flows …
feat: support Conditional Create (mediation) for auto-register flows …
feat: support Conditional Create (mediation) for auto-register flows …
feat: support Conditional Create (mediation) for auto-register flows …
feat: support Conditional Create (mediation) for auto-register flows …
feat: support Conditional Create (mediation) for auto-register flows …
Nothing published for this version
fix: enforce HTTPS scheme check in CheckAllowedOrigins fallback path …
fix: enforce HTTPS scheme check in CheckAllowedOrigins fallback path …
fix: add PHPStan type annotations for parse_url() return values in Ch…
fix: add PHPStan type annotations for parse_url() return values in Ch…
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
AuthenticatorAssertionResponseValidator: Add missing word from deprec…
AuthenticatorAssertionResponseValidator: Add missing word from deprec…
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →