* fix(deps): require cbor-php ^3.4 and cose-lib ^4.8
Both dependencies published security advisories. Raising the constraints
guarantees users get the patched releases instead of relying on Composer
picking a recent enough version.
cose-lib 4.8.0 now enforces X.690 section 8.1.3 when parsing an ECDSA
signature: the SEQUENCE length octets must cover exactly the contents
octets. The ES512 left-padding fixture declared 134 content octets while
carrying 135, so it is rejected as malformed. The fixture is corrected to
0x87, the length it always should have had.
* fix(symfony)!: stop registering the non-standard Ed256 and Ed512 algorithms
Ed256 (-260) and Ed512 (-261) sign a SHA-256 or SHA-512 digest of the payload
with pure Ed25519, a construction no specification defines. IANA assigned both
identifiers to unrelated algorithms, WalnutDSA and TurboSHAKE128.
As of 4.8.0, web-auth/cose-lib emits an E_USER_WARNING when either algorithm is
built without an explicit acknowledgement, and the Symfony error handler turns
that warning into an exception in the dev environment, so every attestation or
assertion request answers with a 500 as soon as the algorithm manager is built.
This is the same failure RS1 caused, with the same resolution: the bundle does
not acknowledge a questionable algorithm on behalf of the applications, so the
definitions are removed instead.
BREAKING CHANGE: webauthn.cose.algorithm.ED256 and webauthn.cose.algorithm.ED512
are no longer registered, so the default verification manager no longer accepts
their signatures. The bundle never offered them at the registration, since
public_key_credential_parameters defaults to an empty list, so only the
applications that explicitly added -260 or -261 to that list are affected. They
have to declare the services themselves; autoconfiguration adds them back to the
manager.