WebauthnPolicyApi
extends ManagementSupport
in package
Per-tenant attestation policy governing the §24 ceremonies, and the compliance report over it.
The webauthn_policy namespace handle (CONTRACT.md §27.2), reached as
$client->management()->webauthnPolicy(). Every method here goes through the one shared
ManagementTransport, so §3 CSRF, the §4 cookie jar, the §5 tenant header, §6 TLS, §16
retry and §19 telemetry apply without this class doing anything to opt in (§27.8).
Table of Contents
Methods
- __construct() : mixed
- complianceReport() : array<int, ComplianceReportEntry>
- `GET /api/v1/tenants/{tenant_id}/webauthn/compliance-report`
- forTenant() : static
- A COPY of this handle scoped to `$tenantId` (§27.4 rule 3). See {@see self::inOrg()} for why it copies.
- get() : PolicyResponse
- `GET /api/v1/tenants/{tenant_id}/webauthn/attestation-policy`
- inOrg() : static
- A COPY of this handle scoped to `$orgId` (§27.4 rule 3).
- set() : WebauthnAttestationPolicy
- `PUT /api/v1/tenants/{tenant_id}/webauthn/attestation-policy`
Methods
__construct()
public
__construct(ManagementTransport $transport[, NamespaceScope $scope = new NamespaceScope() ][, string|null $clientOrgId = null ][, string|null $clientTenantId = null ]) : mixed
Parameters
- $transport : ManagementTransport
-
The one wire path (§27.8).
- $scope : NamespaceScope = new NamespaceScope()
-
Per-handle
{org_id}/{tenant_id}overrides. - $clientOrgId : string|null = null
-
The client's own organization id, or
null. - $clientTenantId : string|null = null
-
The client's own tenant id, or
null.
complianceReport()
`GET /api/v1/tenants/{tenant_id}/webauthn/compliance-report`
public
complianceReport() : array<int, ComplianceReportEntry>
GET /api/v1/tenants/{tenant_id}/webauthn/compliance-report.
Returns the server's complete list. This endpoint is NOT paginated, so the result is a
plain list and never a Page (§27.4 rule 4).
Return values
array<int, ComplianceReportEntry>forTenant()
A COPY of this handle scoped to `$tenantId` (§27.4 rule 3). See {@see self::inOrg()} for why it copies.
public
forTenant(string $tenantId) : static
Parameters
- $tenantId : string
Return values
staticget()
`GET /api/v1/tenants/{tenant_id}/webauthn/attestation-policy`
public
get() : PolicyResponse
GET /api/v1/tenants/{tenant_id}/webauthn/attestation-policy.
Return values
PolicyResponseinOrg()
A COPY of this handle scoped to `$orgId` (§27.4 rule 3).
public
inOrg(string $orgId) : static
Returns a new handle rather than mutating this one. An administrator holding a handle to their own organization should not find it repointed at someone else's because an unrelated code path re-scoped a shared object — and on a management surface that failure mode writes to the wrong tenant rather than merely reading from it.
Parameters
- $orgId : string
Return values
staticset()
`PUT /api/v1/tenants/{tenant_id}/webauthn/attestation-policy`
public
set(WebauthnAttestationPolicy $body) : WebauthnAttestationPolicy
PUT /api/v1/tenants/{tenant_id}/webauthn/attestation-policy.
Parameters
- $body : WebauthnAttestationPolicy
-
the request body