Controllers and services
Controllers
The extension registers backend routes for three controller
groups. All controllers use the Json for parsing
JSON request bodies. Login routes use Routes.
(public access). Management and admin routes use
Ajax (AJAX, with Sudo Mode on write
operations). All paths below are relative to /typo3/.
LoginController (public)
Handles the passkey login flow. Routes have
access: public (via Routes.).
POST /passkeys/ login/ options POST /passkeys/ login/ verify
ManagementController (AJAX)
Passkey lifecycle for the current user
(via Ajax). Write operations
require Sudo Mode re-authentication.
POST /*ajax/ passkeys/ manage/ registration/ options POST /*ajax/ passkeys/ manage/ registration/ verify GET /ajax/ passkeys/ manage/ list POST /*ajax/ passkeys/ manage/ rename POST /*ajax/ passkeys/ manage/ remove
AdminController (AJAX, admin)
Administrative operations for any user
(via Ajax). Write operations
require Sudo Mode re-authentication.
GET /ajax/ passkeys/ admin/ list POST /*ajax/ passkeys/ admin/ remove POST /*ajax/ passkeys/ admin/ revoke- all POST /*ajax/ passkeys/ admin/ unlock POST /*ajax/ passkeys/ admin/ update- enforcement POST /*ajax/ passkeys/ admin/ send- reminder POST /*ajax/ passkeys/ admin/ clear- nudge
AdminModuleController (Backend module)
Renders the Admin Tools > Passkey Management
backend module with Dashboard and Help tabs
(via Modules.).
Enforcement status (AJAX)
Provides enforcement status for the banner.
GET /ajax/ passkeys/ enforcement/ status
Routes marked with * are protected by TYPO3's Sudo Mode.
When accessed without a recent password verification, they
return HTTP 422 with sudo data. The
JavaScript handles this transparently by showing a password
dialog and retrying the request.
Service classes
WebAuthnService
Orchestrates WebAuthn ceremonies using
web- v5.x. Handles registration
options, attestation verification, assertion options,
and assertion verification.
ChallengeService
Generates and verifies HMAC-signed challenge tokens with nonce replay protection.
CredentialRepository
Database access layer for
tx_. Uses
Connection directly (no Extbase).
RateLimiterService
Per-endpoint rate limiting by IP and account lockout after configurable failed attempts. Uses TYPO3 caching framework.
ExtensionConfigurationService
Reads extension configuration and computes effective
values for rp and origin (auto-detection
from request).
EnforcementService
Determines the effective enforcement level for a user by resolving their group memberships (strictest level wins, shortest grace period wins).
AdoptionStatsService
Provides adoption statistics for the admin dashboard: overall counts, per-group breakdowns, users without passkeys, and grace period status.
JavaScript modules
Passkey-- Login form passkey button and WebAuthn flowLogin. js Passkey-- User Settings passkey management panelManagement. js Passkey-- Encourage-stage onboarding bannerBanner. js Passkey-- Admin dashboard enforcement controlsDashboard. js Passkey-- Admin passkey info in user recordsAdmin Info. js