Download the PHP package spomky-labs/dbsc-bundle without Composer
On this page you can find all versions of the php package spomky-labs/dbsc-bundle. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download spomky-labs/dbsc-bundle
More information about spomky-labs/dbsc-bundle
Files in spomky-labs/dbsc-bundle
Package dbsc-bundle
Short Description Device Bound Session Credentials (DBSC) for Symfony - protect sessions from cookie theft with hardware-bound keys.
License MIT
Homepage https://github.com/spomky-labs
Informations about the package dbsc-bundle
DBSC Bundle
Device Bound Session Credentials (DBSC) for Symfony. It protects authenticated sessions from cookie theft by binding them to a hardware-backed private key (TPM) held by the user's browser.
Status: early work in progress. The DBSC specification is still a draft shipping behind a Chrome origin trial, so header names and payloads may change.
What it does
DBSC complements your existing authentication (passwords, WebAuthn, SSO). It does not change how users log in: it hardens the credential that follows. After login the browser generates a device-bound key pair and proves possession of it periodically, so a stolen cookie replayed from another machine stops working. The browser drives all the cryptography; the server side is one response header plus two endpoints, all provided by this bundle. Browsers without DBSC support degrade gracefully.
Installation
Getting started
In additive mode a short, device-bound cookie is issued alongside your existing session, which stays authoritative. You opt in at login and allow the two endpoints; the firewall is unchanged.
When you are ready, DBSC can take over the long-lived credential (the remember-me role) with a
single firewall key (device_bound_session: true).
See Adoption modes for both, including the opt-in badge and the access control to define.
Documentation
Full documentation lives in doc/:
- Concepts and security model
- Installation
- Configuration reference
- Adoption modes
- Migrating from remember-me
- Protocol and endpoints
- Production storage
- Extending the bundle
License
MIT. See LICENSE.
All versions of dbsc-bundle with dependencies
psr/clock Version ^1.0
psr/log Version ^1.1|^2.0|^3.0
symfony/config Version ^7.4|^8.0
symfony/dependency-injection Version ^7.4|^8.0
symfony/http-foundation Version ^7.4|^8.0
symfony/http-kernel Version ^7.4|^8.0
symfony/routing Version ^7.4|^8.0
symfony/security-bundle Version ^7.4|^8.0
symfony/security-core Version ^7.4|^8.0
symfony/security-http Version ^7.4|^8.0
web-token/jwt-library Version ^4.0