Developer Guide
This chapter is for developers who want to understand, debug, or extend the extension.
Architecture overview
The extension is layered as follows:
Classes/
Authentication/ PSR-7-based auth service (TYPO3 auth chain)
Configuration/ Configuration value objects
Controller/ eID dispatcher + Extbase-less controllers
Domain/
Dto/ Request/response DTOs
Enum/ EnforcementLevel enum (re-exported)
Model/ FrontendCredential, RecoveryCode
Event/ PSR-14 event classes (7 events)
EventListener/ PSR-14 listeners (felogin integration, banner)
Form/Element/ PasskeyFeInfoElement (TCA read-only display)
Middleware/ PasskeyPublicRouteResolver + Interstitial
Service/ Business logic (8 services)
Copied!
Key services:
- FrontendWebAuthnService -- WebAuthn ceremony orchestration
- SiteConfigurationService -- Per-site RP ID and origin resolution
- FrontendCredentialRepository -- Credential CRUD operations
- FrontendUserLookupService --
fe_lookup by username/UID (separated from credential repository for single-responsibility)users - FrontendEnforcementService -- Enforcement level resolution
- RecoveryCodeService -- Recovery code generation and verification
- PasskeyEnrollmentService -- Enrollment ceremony coordination
- FrontendAdoptionStatsService -- Adoption statistics for admin module
All services are wired via Symfony DI (Configuration/).
The auth service and eID dispatcher use General
for compatibility with the TYPO3 auth chain.
Token-based login flow
The extension uses a two-phase login flow:
- eID verification: The JavaScript calls the eID endpoint
(
loginorVerify recovery). The eID controller verifies the WebAuthn assertion (or recovery code) and stores the authenticatedVerify fe_UID in a short-lived cache token (user nr_cache, 2-minute TTL).passkeys_ fe_ nonce - felogin form submission: The JavaScript submits a standard
logintype=loginform to the current page, passing the cache token in a hiddenpasskeyfield. TYPO3's normal authentication chain picks this up.Login Token - Auth service resolution:
Passkey(priority 80) reads theFrontend Authentication Service passkeyfromLogin Token $login, looks up the UID in the cache, and returns the user row. No site context or WebAuthn libraries are needed at this stage.Data
This approach ensures the user gets a proper TYPO3 frontend session with all middleware (enforcement interstitial, session regeneration) applied, rather than a bare eID-only response.