Database and monitoring
Credential lifecycle
Passkeys go through the following states:
- Registered -- The credential is created via the
management API and stored in the
tx_table.nrpasskeysbe_ credential - Active -- The credential is used for successful
logins. The
last_andused_ at sign_fields are updated on each use.count - Revoked -- An administrator revokes the credential
via the admin API. The
revoked_timestamp andat revoked_admin UID are recorded. Revoked credentials remain in the database but are rejected during authentication.by - Deleted -- A user removes their own credential via
the management API. The record is soft-deleted
(
deleted = 1).
Database table
The extension uses a single table
tx_ with the following schema:
| Column | Type | Description |
|---|---|---|
uid | int | Primary key (auto-increment) |
be_ | int | FK to be_ |
credential_ | varbinary | WebAuthn credential ID (unique) |
public_ | blob | COSE-encoded public key |
sign_ | int | Signature counter (replay detection) |
user_ | varbinary | WebAuthn user handle (SHA-256 hash) |
aaguid | char(36) | Authenticator attestation GUID |
transports | text | JSON array of transport hints |
discoverable | tinyint(1) | Whether the browser stored the passkey as a discoverable (resident) credential: 1 yes, 0 no, NULL unknown. NULL covers passkeys registered before 1.0.0 and authenticators that report nothing. Only a discoverable passkey can appear in the browser's autofill menu. |
label | varchar(128) | User-assigned label |
created_ | int | Unix timestamp of creation |
last_ | int | Unix timestamp of last use |
revoked_ | int | Unix timestamp of revocation (0=active) |
revoked_ | int | UID of revoking admin (0=not revoked) |
deleted | tinyint | Soft delete flag |
Monitoring
The extension logs all significant events using the PSR-3 logging interface:
- Successful passkey registrations
- Successful passkey logins
- Failed authentication attempts (with hashed username and IP)
- Admin credential revocations
- Admin account unlocks
- Rate limit and lockout triggers
Configure TYPO3 logging writers to capture these events. Example for file logging:
Logging configuration for passkey events
$GLOBALS['TYPO3_CONF_VARS']['LOG']
['Netresearch']['NrPasskeysBe']
['writerConfiguration'] = [
\Psr\Log\LogLevel::INFO => [
\TYPO3\CMS\Core\Log\Writer\FileWriter::class
=> [
'logFileInfix' => 'passkeys',
],
],
];
Copied!