OpaqueEnrollment
in package
implements
JsonSerializable
The client-supplied half of an OPAQUE enrolment, as it appears inside registration / change-password / reset-completion / bootstrap request bodies. There is no standalone `register/finish` endpoint, deliberately. A record can only be created at a moment when the plaintext password legitimately exists on the client, and every one of those moments is already an endpoint that takes a password. A free-standing finish would be an endpoint whose only job is to attach a credential to an account, which is a thing worth not having. Kept separate from [`CreateOpaqueCredential`] because the tenant, the user and the credential identifier are all decided by the server — a client that could name them could enrol a record against somebody else's account.
Table of Contents
Interfaces
- JsonSerializable
Properties
- $opaqueSession : string
- $registrationRecord : string
Methods
- __construct() : mixed
- Constructs a OpaqueEnrollment.
- fromArray() : self
- Rebuilds a OpaqueEnrollment from one decoded JSON object.
- jsonSerialize() : array<string, mixed>
- Renders this object for `json_encode()`.
- toArray() : array<string, mixed>
- Renders this object back to its wire form.
Properties
$opaqueSession read-only
public
string
$opaqueSession
$registrationRecord read-only
public
string
$registrationRecord
Methods
__construct()
Constructs a OpaqueEnrollment.
public
__construct(string $opaqueSession, string $registrationRecord) : mixed
Parameters
- $opaqueSession : string
-
The
opaque_sessionfrom the register/start response, echoed verbatim. - $registrationRecord : string
-
Lowercase-hex serialized RFC 9807
RegistrationRecord.
fromArray()
Rebuilds a OpaqueEnrollment from one decoded JSON object.
public
static fromArray(array<string, mixed> $data) : self
Parameters
- $data : array<string, mixed>
-
The raw wire object.
Return values
selfjsonSerialize()
Renders this object for `json_encode()`.
public
jsonSerialize() : array<string, mixed>
Any Sensitive it carries stays WRAPPED here, so a log line or a
json_encode($model) in application code prints [SENSITIVE]. The one place a secret
is revealed is ManagementTransport, on the way to the wire
and nowhere else (§27.5).
Return values
array<string, mixed>toArray()
Renders this object back to its wire form.
public
toArray() : array<string, mixed>
§27.4 rule 5: a null property is OMITTED, not emitted as null. On a sparse update those two say opposite things — "leave this alone" versus "set this to nothing" — and only omission means the first.