Skip to content

feat: Fire an event when a passkey is revoked - #543

Merged
hellopablo merged 1 commit into
developfrom
feature/passkey-revoke-mfa-cleanup-event
Sep 11, 2026
Merged

hellopablo merged 1 commit into
developfrom
feature/passkey-revoke-mfa-cleanup-event

Conversation

@hellopablo

Copy link
Copy Markdown
Member

Summary

Adds Events::USER_DID_REMOVE_PASSKEY, dispatched from Service\Passkey::revoke() after a successful delete — regardless of what triggered it (self-service /auth/passkeys or the admin user tab). This is a live event alongside the existing did_remove_passkey audit-log entry, not a replacement for it.

Why

Found while building MFA passkey support: revoking a user's last passkey (e.g. from admin) left them enrolled in the MFA module's "Passkey" method with no way to ever satisfy it again — no matching credential exists any more. There was no hook for anything outside this module to react to a passkey disappearing.

The MFA driver (a follow-up PR, nails/driver-multi-factor-auth-passkey) subscribes to this event and un-enrolls the passkey MFA method once a user has zero passkeys left. This lives here rather than as a hard dependency, so module-auth never needs to know MFA exists.

Testing

  • composer test — 218/218 passing
  • composer analyse — clean
  • Verified live: revoked a passkey via /auth/passkeys, confirmed the event fires and (with the driver installed) the dependent MFA method is correctly removed, with no other passkeys affected when more than one remains.

🤖 Generated with Claude Code

Adds Events::USER_DID_REMOVE_PASSKEY, dispatched from Service\Passkey::revoke()
after a successful delete, regardless of what triggered it (self-service or
admin). This is a live event alongside the existing did_remove_passkey audit
log entry, not a replacement for it.

Without this there was no way for anything outside this module to notice a
passkey had gone and react — needed by the MFA module's passkey driver, which
must un-enroll the "Passkey" MFA method once a user's last passkey is revoked,
otherwise they are left enrolled in a method they can never again satisfy.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@hellopablo
hellopablo merged commit b491c00 into develop Sep 11, 2026
4 checks passed
@hellopablo
hellopablo deleted the feature/passkey-revoke-mfa-cleanup-event branch September 11, 2026 14:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant