User Entity

It's all about users

User Entity Class

A User Entity object represents a user in the Webauthn context. It has the following constraints:

  • The user ID must be unique and must be a string,

  • The username must be unique,

Hereafter a minimalist example of user entity:

<?php

use Webauthn\PublicKeyCredentialUserEntity;

$userEntity = PublicKeyCredentialUserEntity::create(
    'john.doe',                             // Username
    'ea4e7b55-d8d0-4c7e-bbfa-78ca96ec574c', // ID
    'John Doe'                              // Display name
);

The username can be composed of any displayable characters, including emojis. Username "😝🥰😔" is perfectly valid.

Developers should not add rules that prevent users from choosing the username they want.

As for the rp Entity, the User Entity may have an icon. This icon must also be secured.

<?php

use Webauthn\PublicKeyCredentialUserEntity;

$userEntity = PublicKeyCredentialUserEntity::create(
    'john.doe',
    'ea4e7b55-d8d0-4c7e-bbfa-78ca96ec574c',
    'John Doe',
    ''
);

The Webauthn specification does not set any limit for the length of the icon.

User Entity Repository

Except if you use the Symfony bundle, there is no interface to implement or abstract class to extend, making it easy to integrate into your application. You may already have a user repository that can be adapted.

Your repository needs to provide these main operations:

  1. Find a user by username (for authentication)

  2. Find a user by user handle (for usernameless authentication)

  3. Create a new user entity (during registration)

Repository Example

Here's a simple example using an array storage (for demonstration purposes):

<?php

declare(strict_types=1);

namespace App\Repository;

use Webauthn\PublicKeyCredentialUserEntity;

final class InMemoryUserEntityRepository
{
    private array $users = [];

    public function createUserEntity(
        string $username,
        string $displayName,
        ?string $icon = null
    ): PublicKeyCredentialUserEntity {
        $userHandle = random_bytes(64); // Generate unique user ID

        $userEntity = PublicKeyCredentialUserEntity::create(
            $username,
            $userHandle,
            $displayName,
            $icon
        );

        $this->users[$userHandle] = $userEntity;

        return $userEntity;
    }

    public function findOneByUsername(string $username): ?PublicKeyCredentialUserEntity
    {
        foreach ($this->users as $userEntity) {
            if ($userEntity->name === $username) {
                return $userEntity;
            }
        }

        return null;
    }

    public function findOneByUserHandle(string $userHandle): ?PublicKeyCredentialUserEntity
    {
        return $this->users[$userHandle] ?? null;
    }
}

For production use, implement your repository with your preferred storage backend. See the Symfony Bundle section for a complete Doctrine example.

Important Notes About User ID (userHandle)

  • Must be unique: Each user must have a unique user ID

  • Must be persistent: The user ID must never change for a given user

  • Should be random: Use at least 32 bytes of random data (64 bytes recommended)

  • Must not be PII: Do not use email, username, or any personally identifiable information

  • Maximum 64 bytes: The WebAuthn specification limits user IDs to 64 bytes

<?php

// Good examples
$userHandle = random_bytes(64); // Cryptographically secure random bytes
$userHandle = Uuid::v4()->toBinary(); // UUID v4 (16 bytes)

// Bad examples - DO NOT USE
$userHandle = $email; // Email can change and is PII
$userHandle = (string) $autoIncrementId; // Sequential IDs are predictable
$userHandle = hash('sha256', $username); // Derived from username, not random

Last updated

Was this helpful?