Skip to content

Passkeys, Blade components, and login improvements#207

Open
produktive wants to merge 42 commits into
thedevdojo:mainfrom
produktive:main
Open

Passkeys, Blade components, and login improvements#207
produktive wants to merge 42 commits into
thedevdojo:mainfrom
produktive:main

Conversation

@produktive

@produktive produktive commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Register x-auth:: anonymous Blade component path in AuthServiceProvider
  • Align config/passkeys.php with Laravel Passkeys (origins, middleware, throttle)
  • Add passkey registration component and optional reloadOnSuccess for passkey verify
  • Clean up login Livewire page and apply GuestUnlessPreview middleware

Test plan

  • Passkey registration on security/settings flow
  • Passkey login with and without reload-on-success
  • Standard email/password login and 2FA
  • Auth setup preview routes

Made with Cursor

produktive and others added 26 commits July 13, 2026 11:40
Drop Volt and Folio in favor of Livewire 4 single-file page components,
require Livewire 4 and Laravel 12+, and add configurable passkey sign-in
with a dedicated /auth/setup/passkeys screen.

Co-authored-by: Cursor <[email protected]>
Fix setup preview stacking, add an upgrade guide, and clean up static analysis and code style so the Livewire 4 and passkeys branch is ready for review.

Co-authored-by: Cursor <[email protected]>
Register the Tests namespace for DuskTestCase, add CreatesApplication for the CI Laravel app harness, and expand the upgrade guide with $event.target migration notes.

Co-authored-by: Cursor <[email protected]>
Walk up from the package tests directory to find the consuming app's bootstrap/app.php in CI instead of assuming it lives beside the tests folder.

Co-authored-by: Cursor <[email protected]>
Ensures x-auth::elements.* resolves correctly when views are consumed from the package path.

Co-authored-by: Cursor <[email protected]>
Uses allowed_origins, middleware, and throttle:6,1 so passkey routes work out of the box.

Co-authored-by: Cursor <[email protected]>
…y login.

Includes passkey-registration component, passkeyReloadOnSuccess prop on social-providers, and rebuilt auth styles.

Co-authored-by: Cursor <[email protected]>
…ware.

Removes unused page title property and wires GuestUnlessPreview for auth setup flows.

Co-authored-by: Cursor <[email protected]>
produktive and others added 3 commits July 22, 2026 22:14
Component #[Middleware] attributes are not honored by Route::livewire(), so
auth routes lacked the web group and protected pages saw a null user.

Co-authored-by: Cursor <[email protected]>
Improve Remember Me checkbox contrast and peer-checked behavior, simplify secondary button styling, and replace the incorrect chat bubble with a fingerprint icon on the setup page.

Co-authored-by: Cursor <[email protected]>
Use the auth container component and correct the Enable button closing tag so the page renders properly.

Co-authored-by: Cursor <[email protected]>
produktive and others added 13 commits July 22, 2026 23:43
Pipeline: :through() cannot resolve route middleware group aliases, so use the TwoFactorChallenged class directly.
Co-authored-by: Cursor <[email protected]>
Pipeline: :through() cannot resolve middleware aliases directly, so resolve them through the router before executing the 2FA challenge middleware stack.
Co-authored-by: Cursor <[email protected]>
…fy throttle.

Livewire 4 full-page components ignore Laravel controller middleware attributes;
route middleware is the source of truth. Drop redundant #[Middleware] usage from
auth SFCs and re-add throttle:6,1 to the verification notice route.

Co-authored-by: Cursor <[email protected]>
Replace document.getElementById wire:click calls with auth_code property
access, route paste auto-submit through $wire.submitCode, sync the hidden
pin input to wire:model, and reset auto-submit state after failed attempts.

Co-authored-by: Cursor <[email protected]>
Remove dead Livewire SFC middleware attributes and restore verify throttle
Drop Dusk, page objects, and duskapiconf in favor of pest-plugin-browser and Playwright. Fix the CI harness TestCase for the Laravel app symlink pattern and update workflows to install Playwright instead of ChromeDriver.

Co-authored-by: Cursor <[email protected]>
Assert redirects to /login (the named login route) instead of auth/login, and drop /auth/verify from public URL smoke tests since it requires authentication.

Co-authored-by: Cursor <[email protected]>
Two-factor challenge middleware redirects to auth/login, while auth middleware on the setup page redirects to the named /login route.

Co-authored-by: Cursor <[email protected]>
Drop --with-deps to avoid long apt installs on slow runners, and cache ~/.cache/ms-playwright so matrix jobs reuse Chromium downloads.

Co-authored-by: Cursor <[email protected]>
Replace Laravel Dusk with Pest 4 browser testing
Recovery codes inherited light text from the auth layout without an explicit light-mode color, making them invisible on the gray background.

Co-authored-by: Cursor <[email protected]>
Fix unreadable two-factor recovery codes text color
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant