“”

Passkeys Backend Authentication Passkeys Backend Authentication

2 likes

nr_passkeys_be / beta

Passwordless TYPO3 backend authentication via Passkeys (WebAuthn/FIDO2). Enables one-click login with TouchID, FaceID, YubiKey, Windows Hello. By Netresearch.

This version supports TYPO3

12 LTS 13 LTS 14 LTS

Older versions also support TYPO3

12 LTS 13 LTS 14 LTS


Tags

Get started

Download 0.10.0

Details

Author
Netresearch DTT GmbH
Company
Netresearch DTT GmbH
Last update
25. Jun 2026
First upload
10. Feb 2026
Downloads
1,413
Category
Backend
Dependencies
  • TYPO3 (>=12.4.0 <=14.99.99)
  • PHP (>=8.2.0 <=8.99.99)
  • setup (>=12.4.0 <=14.99.99)
  • backend (>=12.4.0 <=14.99.99)

Last upload comment

- chore(release): v0.10.0 (#81)
- chore(release): v0.10.0
- fix(ratelimit): close rate-limit check/record TOCTOU with atomic consume (#80)
- fix(admin): enforce system-maintainer boundary on passkey admin API (#78)
- fix: narrow interstitial AJAX exemption + fail closed on Host-derived rpId/origin (#79)
- fix(auth): enforce discoverableLoginEnabled on the auth-service login path (#77)
- test(ratelimit): clarify consume-rate-limit tests and ordering
- fix(ratelimit): close rate-limit check/record TOCTOU with atomic consume
- fix(config): only enforce host-trust when a request Host header is present
- test+docs: review follow-ups for host-binding and interstitial scope
- fix(config): fail closed when deriving rpId/origin from an untrusted Host
- fix(middleware): narrow interstitial AJAX exemption to enrollment routes
- fix(auth): enforce discoverableLoginEnabled on the auth-service login path
- fix(admin): normalize system-maintainer IDs without a string callable
- refactor(admin): dedupe maintainer-guard literal and tests (SonarCloud)
- fix(admin): extend system-maintainer guard to reminder/clear-nudge endpoints
- fix(admin): enforce system-maintainer boundary on passkey admin API
- ci: adopt canonical typo3-extension template (#71)
- ci: ignore Django CSRF false-positive on Fluid template
- refactor(js): share WebAuthn base64 helpers + modernize login to ES module (TEST-1) (#76)
- refactor(js): share WebAuthn base64 helpers, modernize login to an ES module (TEST-1)
- refactor(service): split WebAuthnService into attestation + assertion ceremonies (ARCH-2) (#75)
- fix(admin): dashboard infobox rendering + i18n + real documentation screenshots (#74)
- refactor(service): split WebAuthnService into attestation + assertion ceremonies
- feat(i18n): make the admin Help page fully translatable
- feat(i18n): make dashboard onboarding infoboxes translatable
- docs: replace plac

For details see https://github.com/netresearch/t3x-nr-passkeys-be/releases


Downloads by month

Installation

  1. Download ZIP file
  2. Log into your TYPO3 backend
  3. Go to Extension Manager module
  4. Press the upload button on the top bar
  5. Select the ZIP file and upload it. If you want to overwrite an existing extension installation, activate the checkbox.
  1. Go to your folder where the root composer.json file is located
  2. Type: composer require netresearch/nr-passkeys-be to get the latest version that runs on your TYPO3 version.
  1. Download T3X file
  2. Log into your TYPO3 backend
  3. Go to Extension Manager module
  4. Press the upload button on the top bar
  5. Select the T3X file and upload it. If you want to overwrite an existing extension installation, activate the checkbox.

Other extensions by this user (14)


Version history

Filter for TYPO3 versions

0.10.0 beta Latest
June 25, 2026
TYPO3: 12 LTS 13 LTS 14 LTS (>=12.4.0 <=14.99.99)
- chore(release): v0.10.0 (#81)
- chore(release): v0.10.0
- fix(ratelimit): close rate-limit check/record TOCTOU with atomic consume (#80)
- fix(admin): enforce system-maintainer boundary on passkey admin API (#78)
- fix: narrow interstitial AJAX exemption + fail closed on Host-derived rpId/origin (#79)
- fix(auth): enforce discoverableLoginEnabled on the auth-service login path (#77)
- test(ratelimit): clarify consume-rate-limit tests and ordering
- fix(ratelimit): close rate-limit check/record TOCTOU with atomic consume
- fix(config): only enforce host-trust when a request Host header is present
- test+docs: review follow-ups for host-binding and interstitial scope
- fix(config): fail closed when deriving rpId/origin from an untrusted Host
- fix(middleware): narrow interstitial AJAX exemption to enrollment routes
- fix(auth): enforce discoverableLoginEnabled on the auth-service login path
- fix(admin): normalize system-maintainer IDs without a string callable
- refactor(admin): dedupe maintainer-guard literal and tests (SonarCloud)
- fix(admin): extend system-maintainer guard to reminder/clear-nudge endpoints
- fix(admin): enforce system-maintainer boundary on passkey admin API
- ci: adopt canonical typo3-extension template (#71)
- ci: ignore Django CSRF false-positive on Fluid template
- refactor(js): share WebAuthn base64 helpers + modernize login to ES module (TEST-1) (#76)
- refactor(js): share WebAuthn base64 helpers, modernize login to an ES module (TEST-1)
- refactor(service): split WebAuthnService into attestation + assertion ceremonies (ARCH-2) (#75)
- fix(admin): dashboard infobox rendering + i18n + real documentation screenshots (#74)
- refactor(service): split WebAuthnService into attestation + assertion ceremonies
- feat(i18n): make the admin Help page fully translatable
- feat(i18n): make dashboard onboarding infoboxes translatable
- docs: replace plac

For details see https://github.com/netresearch/t3x-nr-passkeys-be/releases
Download
0.9.4 beta
June 08, 2026
TYPO3: 12 LTS 13 LTS 14 LTS (>=12.4.0 <=14.99.99)
- chore(release): v0.9.4 (#69)
- chore(release): v0.9.4
- feat(backend): use FIDO passkey mark for module and login icon (#68)
- style(backend): use SVG presentation attributes in v14 module icon
- style(backend): make v14 module icon duotone with NR-teal key
- feat(backend): use FIDO passkey mark for module and login icon
- test(e2e): target the backend module iframe by id (#67)
- test(e2e): target the backend module iframe by id

For details see https://github.com/netresearch/t3x-nr-passkeys-be/releases
Download
0.9.3 beta
May 28, 2026
TYPO3: 12 LTS 13 LTS 14 LTS (>=12.4.0 <=14.99.99)
- chore: release v0.9.3 (#65)
- chore: release v0.9.3
- test(setup): cover v14 panel FormEngine wiring + assert E2E render (#64)
- test(setup): cover v14 panel FormEngine wiring + assert E2E render

For details see https://github.com/netresearch/t3x-nr-passkeys-be/releases
Download
0.9.0 beta
May 03, 2026
TYPO3: 12 LTS 13 LTS 14 LTS (>=12.4.0 <=14.99.99)
- release: v0.9.0 (#58)
- release: v0.9.0
- chore: support TYPO3 14.3 LTS (incl. webauthn-lib 5.3 migration) (#57)
- refactor: replace deprecated GeneralUtility::getIndpEnv() with NormalizedParams
- ci: grant actions:read to reusable workflow callers
- chore(deps): raise web-auth/webauthn-lib floor to ^5.3
- chore(typo3): bump TYPO3 14.x baseline to ^14.3 LTS
- refactor(webauthn): migrate to web-auth/webauthn-lib 5.3 CredentialRecord API

For details see https://github.com/netresearch/t3x-nr-passkeys-be/releases
Download
0.8.2 beta
April 23, 2026
TYPO3: 12 LTS 13 LTS 14 LTS (>=12.4.0 <=14.99.99)
- chore: release v0.8.2 (#56)
- chore: release v0.8.2
- fix(docs): replace Documentation/CLAUDE.md symlink with real file (unblocks Intercept render) (#55)
- fix(docs): replace Documentation/CLAUDE.md symlink with file copy

For details see https://github.com/netresearch/t3x-nr-passkeys-be/releases
Download
0.8.1 beta
April 23, 2026
TYPO3: 12 LTS 13 LTS 14 LTS (>=12.4.0 <=14.99.99)
- chore: release v0.8.1 (#54)
- chore(changelog): fix workflow path + cross-repo PR references
- chore: release v0.8.1
- chore: adopt release-typo3-extension orchestrator (#53)
- docs(workflows): update AGENTS.md to reflect orchestrator adoption
- chore: adopt release-typo3-extension orchestrator

For details see https://github.com/netresearch/t3x-nr-passkeys-be/releases
Download
0.8.0 beta
April 23, 2026
TYPO3: 12 LTS 13 LTS 14 LTS (>=12.4.0 <=14.99.99)
## Changes
- chore: release v0.8.0 (#52)
- chore: release v0.8.0
- feat(auth): add skipMfaOnPasskeyAuth to resolve MFA-policy dilemma (#50)
- test(e2e): fixme own mfa-bypass spec pending rpId infra fix
- ci: pick up typo3-ci-workflows npm lockfile fix
- ci: trigger fresh run to pick up typo3-ci-workflows cms-install fix
- ci: trigger fresh run to pick up typo3-ci-workflows e2e fix
- fix(config): defensive fallback for skipMfaOnPasskeyAuth
- test(functional): enable BypassFinals in functional bootstrap
- test(e2e): Playwright coverage for MFA bypass during passkey login
- test(auth): functional test for MFA session-key round-trip
- feat(auth): add skipMfaOnPasskeyAuth setting (default enabled)
- test(e2e): triage 6 pre-existing broken specs with .fixme() (#51)
- test(e2e): triage pre-existing broken specs with .fixme()

## Installation

```bash
composer require netresearch/nr-passkeys-be
```

## Security

All release artifacts are signed with [Sigstore](https://www.sigstore.dev/) keyless signing.

### Verify signatures

```bash
cosign verify-blob \
--bundle nr-passkeys-be-0.8.0.zip.bundle \
--certificate-identity-regexp "https://github.com/netresearch/.*" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
nr-passkeys-be-0.8.0.zip
```

### Verify checksums

```bash
sha256sum -c checksums.txt
```

## Software Bill of Materials (SBOM)

SBOMs are provided in both SPDX and CycloneDX formats for supply chain transparency.

For details see https://github.com/netresearch/t3x-nr-passkeys-be/releases
Download
0.6.0 beta
March 01, 2026
TYPO3: 12 LTS 13 LTS 14 LTS (>=12.4.0 <=14.99.99)
Features

- Per-group passkey enforcement with 4 levels: Off, Encourage, Required, Enforced
- Configurable grace periods for Required enforcement (1–365 days)
- PSR-15 interstitial middleware prompting users to register passkeys (skippable during grace period, mandatory after expiry)
- Encourage-stage dismissible banner with passkey explanation, docs link, and administrator contact guidance (supports TYPO3 v12/v13/v14)
- Admin dashboard backend module (Admin Tools Passkey Management) with adoption statistics, per-group enforcement controls, and user list
- Admin actions: Send Reminder (nudge), Clear Nudge, Revoke All
- `EnforcementLevel` enum, `EnforcementStatus` DTO, `EnforcementService`, `AdoptionStatsService`
- `PasskeyBanner.js`, `PasskeyDashboard.js` JavaScript modules
- TCA fields `passkey_enforcement` and `passkey_grace_period_days` on `be_groups`
- 5 new admin AJAX endpoints for enforcement and nudge management
- 153 i18n translation units across 4 XLF files
- Context-sensi

Details: https://github.com/netresearch/t3x-nr-passkeys-be/releases/tag/v0.6.0
Download
0.5.0 beta
February 25, 2026
TYPO3: 12 LTS 13 LTS 14 LTS (>=12.4.0 <=14.99.99)
Features

- Per-user password login enforcement: `disablePasswordLogin` now blocks passwords only for users who have registered passkeys, enabling gradual onboarding without locking out new users ([25](https://github.com/netresearch/t3x-nr-passkeys-be/pull/25))
- Deployment Scenarios documentation: new chapter covering multi-environment setup, database sync, user onboarding, shared rpId considerations, containerized deployments, and local DDEV development ([26](https://github.com/netresearch/t3x-nr-passkeys-be/pull/26))

Architecture Decision Records

- [ADR-0001](https://github.com/netresearch/t3x-nr-passkeys-be/blob/main/docs/adr/0001-per-user-password-enforcement.md): Per-user password enforcement decision
- [ADR-0002](https://github.com/netresearch/t3x-nr-passkeys-be/blob/main/docs/adr/0002-no-rpid-aware-enforcement.md): No rpId-aware enforcement (security rationale)

Upgrade notes

- `disablePasswordLogin` behavior changed: previously a no-op global kill-switch, now enforces pe

Details: https://github.com/netresearch/t3x-nr-passkeys-be/releases/tag/0.5.0
Download
0.4.1 beta
February 18, 2026
TYPO3: 12 LTS 13 LTS 14 LTS (>=12.4.0 <=14.99.99)
Security

- Harden challenge nonce replay protection — nonce verification now uses atomic exclusive locking to prevent TOCTOU race conditions; error responses genericized to avoid leaking internal state (18)

Documentation

- Production deployment security requirements — new documentation section covering trusted hosts pattern, reverse proxy IP detection, and multi-server cache backend configuration (19)

Dependencies

- Update `saschaegerer/phpstan-typo3` from 2.0 to 3.0 (16, dev-only)

Full Changelog: https://github.com/netresearch/t3x-nr-passkeys-be/compare/0.4.0...0.4.1

Details: https://github.com/netresearch/t3x-nr-passkeys-be/releases/tag/0.4.1
Download
0.4.0 beta
February 16, 2026
TYPO3: 12 LTS 13 LTS 14 LTS (>=12.4.0 <=14.99.99)
What's New

- TYPO3 12.4 LTS support — the extension now supports TYPO3 v12.4 through v14.x (PHP 8.2)
- Event listener registered via Services.yaml tag for v12 compatibility
- FormEngine DI-aware `PasskeyInfoElement` with `setData()` for v12 `NodeFactory`
- CI matrix expanded to 40 jobs covering all three TYPO3 LTS versions
- DDEV development environment includes v12 installation

Other Changes

- OpenSSF Scorecard improved from 6.3 to 9 (14)
- JavaScript tests added to CI (13)
- Dependency updates: CodeQL action bumps (15)

Full Changelog: https://github.com/netresearch/t3x-nr-passkeys-be/compare/0.3.0...0.4.0

Details: https://github.com/netresearch/t3x-nr-passkeys-be/releases/tag/0.4.0
Download
0.3.0 beta
February 12, 2026
TYPO3: 13 LTS 14 LTS (>=13.4.0 <=14.99.99)
What's Changed

Refactor
- Use TYPO3 native JS APIs in PasskeyManagement (11) — Replaced custom IIFE with ES module using TYPO3's `AjaxRequest`, `Notification`, `Modal`, `SeverityEnum`, `sudoModeInterceptor`, and `DocumentService`. Fixes sudo mode rendering in v14 iframe.

Features
- Inline name input for passkey registration (12) — Users can now name their passkey before registering it. Input field next to the "Add Passkey" button with accessible `aria-label`, disabled during registration, and reset after success.

Fixes
- Escape label in removal modal (XSS prevention)
- Defer DOM initialization with `DocumentService.ready()`
- Resolve `AjaxRequest` responses and check status before showing success
- Replace inline style with CSS class

Full Changelog: https://github.com/netresearch/t3x-nr-passkeys-be/compare/0.2.0...0.3.0

Details: https://github.com/netresearch/t3x-nr-passkeys-be/releases/tag/0.3.0
Download
0.1.1 beta
February 10, 2026
TYPO3: 13 LTS 14 LTS (>=13.4.0 <=14.99.99)
Patch release for TER publishing.

- Fix ext_emconf.php compatibility with TER (remove declare strict_types)
- Fix PHPStan route attribute mapping for CI
- Fix user settings screenshot showing correct Account security tab
- Updated documentation with card-grids, screenshots, current architecture

Details: https://github.com/netresearch/t3x-nr-passkeys-be/releases/tag/0.1.1
Download

Get started

Download 0.10.0

Details

Author
Netresearch DTT GmbH
Company
Netresearch DTT GmbH
Last update
25. Jun 2026
First upload
10. Feb 2026
Downloads
1,413
Category
Backend
Dependencies
  • TYPO3 (>=12.4.0 <=14.99.99)
  • PHP (>=8.2.0 <=8.99.99)
  • setup (>=12.4.0 <=14.99.99)
  • backend (>=12.4.0 <=14.99.99)