NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #2462 most downloaded on Packagist
FIDO2/Webauthn Security Bundle For Symfony
Last release 27 days ago
10 Sep 2026
Release timing varies
gaps range from 1 weeks to 9 months
Rarely documented
notes for 9 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
126 releases · first in 2019
BREAKING CHANGE: webauthn.cose.algorithm.ED256 and webauthn.cose.algorithm.ED512 are no longer registered, so the default verification manager no long…
Both dependencies published security advisories. Raising the constraints
guarantees users get the patched releases instead of relying on Composer
picking a recent enough version.
cose-lib 4.8.0 now enforces X.690 section 8.1.3 when parsing an ECDSA
signature: the SEQUENCE length octets must cover exactly the contents
octets. The ES512 left-padding fixture declared 134 content octets while
carrying 135, so it is rejected as malformed. The fixture is corrected to
0x87, the length it always should have had.
Ed256 (-260) and Ed512 (-261) sign a SHA-256 or SHA-512 digest of the payload
with pure Ed25519, a construction no specification defines. IANA assigned both
identifiers to unrelated algorithms, WalnutDSA and TurboSHAKE128.
As of 4.8.0, web-auth/cose-lib emits an E_USER_WARNING when either algorithm is
built without an explicit acknowledgement, and the Symfony error handler turns
that warning into an exception in the dev environment, so every attestation or
assertion request answers with a 500 as soon as the algorithm manager is built.
This is the same failure RS1 caused, with the same resolution: the bundle does
not acknowledge a questionable algorithm on behalf of the applications, so the
definitions are removed instead.
BREAKING CHANGE: webauthn.cose.algorithm.ED256 and webauthn.cose.algorithm.ED512
are no longer registered, so the default verification manager no longer accepts
their signatures. The bundle never offered them at the registration, since
public_key_credential_parameters defaults to an empty list, so only the
applications that explicitly added -260 or -261 to that list are affected. They
have to declare the services themselves; autoconfiguration adds them back to the
manager.
One column per quarter.
BREAKING CHANGE: webauthn.cose.algorithm.RS1 is no longer registered, so the default verification manager no longer accepts RS1 signatures. The bundle…
RS1 is RSASSA-PKCS1-v1_5 with SHA-1, which is no longer acceptable for digital
signatures. web-auth/cose-lib emits an E_USER_WARNING when the algorithm is
built without an explicit acknowledgement, and the Symfony error handler turns
that warning into an exception in the dev environment, so every attestation or
assertion request answered with a 500 as soon as the algorithm manager was
built.
Acknowledging the algorithm in the service definition would have silenced the
warning while keeping an insecure algorithm in the default verification
manager. The bundle should not make that choice on behalf of the applications,
so the definition is removed instead.
BREAKING CHANGE: webauthn.cose.algorithm.RS1 is no longer registered, so the
default verification manager no longer accepts RS1 signatures. The bundle never
offered RS1 at the registration, since public_key_credential_parameters
defaults to an empty list, so only the applications that explicitly added
COSE_ALGORITHM_RS1 to that list are affected. They have to declare the service
themselves; autoconfiguration adds it back to the manager.
fix(rp-entity): default rp.name to the Relying Party ID when serializ…
fix(rp-entity): default rp.name to the Relying Party ID when serializ…
ci: run PHPUnit without castor and drop the PHP 8.6 matrix entry
The tests job runs inside the phpqa image of the matrix PHP version and
called castor, which requires PHP >= 8.4, so the 8.2 and 8.3 entries
died before running a single test. The job now calls the same PHPUnit
command castor was wrapping.
The 8.6 image is not published, only 8.2 to 8.5 are, so that entry could
only fail at container initialisation. It can come back once the image
exists.
Ref #933
composer.json allows psr/log ^1.0|^2.0|^3.0, so the lowest-deps job
installs psr/log 1.x, whose LoggerInterface::log() takes an untyped
message. The fixture declared the 3.x signature and PHP refused to load
the test suite.
Ref #933
SetList::PHPUNIT, SetList::STRICT and PHPUnitSetList::PHPUNIT_120 have
been removed upstream, so both tools aborted before looking at a single
file. The rules that mattered from the STRICT set are already declared
one by one right below the imports, and the version specific PHPUnit set
is covered by withComposerBased().
RemoveEraseCredentialsRector is skipped: it would delete
eraseCredentials() from a test fixture implementing UserInterface, which
is fatal on Symfony 6.4.
Ref #933
Both tools had been silent for months, so a backlog accumulated: comment
spacing, native function invocation, global namespace imports, redundant
boolean identity comparisons, a readonly class, a dead instanceof assert
and a property default the constructor always overwrites.
Ref #933
Nineteen errors were reported outside the baseline, one of them an
unmatched ignored error on Psr18HttpClient which trips
reportUnmatchedIgnoredErrors. Generated on PHP 8.4, the version the CI
job uses.
Ref #933
fix(security): stop logging the raw Request object in WebauthnAuthent…
fix(security): stop logging the raw Request object in WebauthnAuthent…
fix(security): stop logging the raw Request object in WebauthnAuthent…
fix(security): stop logging the raw Request object in WebauthnAuthent…
fix(creation-profiles): default rp.name to rp.id when empty (#893) (#…
fix(creation-profiles): default rp.name to rp.id when empty (#893) (#…
Nothing published for this version
feat: support Conditional Create (mediation) for auto-register flows …
feat: support Conditional Create (mediation) for auto-register flows …
feat: support Conditional Create (mediation) for auto-register flows …
feat: support Conditional Create (mediation) for auto-register flows …
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →