This is a simple demo application that goes along with firehed/u2f.
Since this demo is showing off authentication with the U2F protocol, you must physically have a FIDO U2F Token. You can get one from Amazon for as little as $6.
The forms in index.html individually show what would happen during user registration and adding a token to a user's account.
Each one is powered by an AJAX handler to shuffle data between the client and server (see site.js)
Each of the PHP files in public/ power one of those AJAX endpoints, so that you can see the general inputs and outputs of each page.
It's a very 2004-era "upload with FTP and you're done" approach, so that you can focus on understanding the pairs of "generate request"/"process response" endpoints.
This is intended to be a very simple example, doing the least amount possible to demonstrate how to use the U2F library. That means it intentionally leaves out best practices you would expect in a larger application: routers, models, DBALs, dependency inversion containers, etc.
In a real application, each of the php files would be some sort of standard controller, API endpoint, etc.
If you're trying to run the example locally, you must do a few things:
composer installpublic/ directoryWhy HTTPS? Because browsers will reject HTTP. You need HTTPS in production for your authentication to be remotely meaningful anyway.
Why Chrome? As if 2016-03-23, only Chrome supports U2F. There is a feature request open for Firefox, with progress underway.
This means you can't just use the built-in PHP webserver. Sorry.
To avoid having to screw around with setting it up locally in a development environment, just use the demo above and watch traffic in the browser's development tools.
Content type
Image
Digest
Size
27.4 MB
Last updated
about 6 years ago
docker pull firehed/webauthn-u2f-demo