- PHP 8.2 or higher
- Symfony 7.4 or 8.0 (security, http-foundation, http-kernel, routing, config)
- A firewall: the bundle relies on the Security component to know who the authenticated user is
The JWS verification relies on web-token/jwt-library, which is pulled in automatically.
composer require spomky-labs/dbsc-bundleWith Symfony Flex the bundle is registered automatically. Without Flex, add it to
config/bundles.php:
return [
// ...
SpomkyLabs\DbscBundle\SpomkyLabsDbscBundle::class => ['all' => true],
];The bundle generates the registration and refresh routes, one pair per firewall that enables DBSC. Import the loader once:
# config/routes/dbsc.yaml
dbsc:
resource: '@SpomkyLabsDbscBundle/config/routes.php'For a firewall named main this yields /dbsc/main/register and /dbsc/main/refresh by default;
override the paths per firewall with the register / refresh options. The routes appear only
once a firewall opts in (see below), so importing the resource on a project with no DBSC firewall
is harmless.
- Enable DBSC on a firewall with
device_bound_session: true. Nothing else is required for additive mode. - Review the configuration reference to tune cookie attributes, the accepted algorithms or the challenge lifetime.
- Before production, replace the default in-memory stores with shared ones: see Production storage.