My name is Florent Morselli (flɔʁɑ̃ mɔʁseli). I am a French web developer and project manager passionate about PHP, ReactJS and Free, Libre & Open-Source Software. As far as possible, I contribute to projects or publish my own work.
🧡 Since early 2025, I am proud to be a
. This allows me to help shape the future of the framework I use and love daily.
The projects I am working on are mainly related to security over web applications. In particular, you will find useful libraries of Symfony bundles for
- One-Time Passwords (TOTP/HOTP) => see https://github.com/Spomky-Labs/otphp,
- Json Web Tokens (JWT, including signed and encrypted ones) => see https://github.com/web-token,
- Web Push => see https://github.com/Spomky-Labs/web-push,
- Concise Binary Object Representation (CBOR) => see https://github.com/Spomky-Labs/cbor-php,
- Webauthn => see https://github.com/web-auth.
Among all of these projects, let me encourage you to read more about Webauthn, a PHP implementation I am working on since end of 2018 and that will help you to get rid of passwords.
In addition, I had the opportunity to share my knowledge during the following events:
- September 2022: I presented the possibilities offered by this technology during the second edition of ApiPlatformCon in September 2022 in Lille, France.
- March 2023, I gave two 1-day workshops during the Symfony Live Paris 2023.
- December 2023, I gave a 1-day workshop during the Symfony Con Brussels 2023.
- March 2024, I presented my feedback on the Progressive Web Apps and gave a 1-day workshop during the Symfony Live 2024.
- March 2025, I gave a 1-day workshop during the Symfony Live 2025
Feel free to ask me about all of these FLOSS projects or reach me on any other topics you may want to discuss.
Hereafter an overview of my involvement in the Open-Source ecosystem. If you wish, you can sponsor me. The GitHub Sponsors page or the Patreon page are made for that purpose. Any help is greatly appreciated and allows me to spend time on these projects.
- symfony/doctrine-orm-key-management - Symfony Doctrine ORM Key Management Bridge (1 day ago)
- symfony/key-management - Abstracts Key Management Systems (AWS KMS, Azure Key Vault, Google Cloud KMS, HashiCorp Vault Transit, KMIP, ...) behind a single interface (1 day ago)
- symfony/security-bundle - Provides a tight integration of the Security component into the Symfony full-stack framework (1 day ago)
- symfony/security-http - Symfony Security Component - HTTP Integration (1 day ago)
- symfony/symfony - The Symfony PHP framework (1 day ago)
- beffroi-php/.github - (3 days ago)
- symfony/doctrine-dbal-key-management - Symfony Doctrine DBAL Key Management Bridge (4 days ago)
- Spomky-Labs/dbsc-bundle - Device Bound Session Credentials (DBSC) for Symfony: protect sessions from cookie theft with hardware-bound keys. (2 weeks ago)
- Spomky-Labs/phpqa - 🐘 Opinionated CI-ready PHP QA Docker image built on top of jakzal/phpqa, extended with Castor and custom CI tasks. (2 weeks ago)
- symfony/azure-keyvault-key-management - Symfony Azure Key Vault Key Management Bridge (2 weeks ago)
- [Security] Let an application reach an endpoint of its OIDC provider through the client on symfony/symfony (1 day ago)
- [Security] Read the keys of an OIDC provider through one object on symfony/symfony (1 day ago)
- [KeyManagement] Let a projection cover several forms of a value, and three fixes on symfony/symfony (1 day ago)
- [KeyManagement] Let a blind index derive its tags under a data key a store holds on symfony/symfony (4 days ago)
- [KeyManagement] Bind a stored data key to its reference and scope on symfony/symfony (4 days ago)
- [Security][SecurityBundle] Accept a DPoP-bound access token only from a request that proves its key on symfony/symfony (6 days ago)
- [Security] Document the form_post response mode of oidc_login on symfony/symfony-docs (1 week ago)
- [Security][SecurityBundle] Bind what an OIDC provider issues to a key the client holds (DPoP) on symfony/symfony (1 week ago)
- [Security][SecurityBundle] Authenticate the OIDC client with its TLS certificate, per RFC 8705 on symfony/symfony (1 week ago)
- [Security] Let the re-authentication entry point say which denials it acts on on symfony/symfony (1 week ago)
- api-platform/core (v5.0.2, 3 days ago) - The server component of API Platform: hypermedia and GraphQL APIs in minutes
- symfony/symfony (v8.1.8, 6 days ago) - The Symfony PHP framework
- symfony/security-http (v8.1.8, 6 days ago) - Symfony Security Component - HTTP Integration
- symfony/validator (v8.1.8, 6 days ago) - Provides tools to validate values
- symfony/security-bundle (v8.1.8, 6 days ago) - Provides a tight integration of the Security component into the Symfony full-stack framework
- symfony/security-core (v8.1.8, 6 days ago) - Symfony Security Component - Core Library
- symfony/framework-bundle (v8.1.8, 6 days ago) - Provides a tight integration between Symfony components and the Symfony full-stack framework
- symfony/web-profiler-bundle (v8.1.8, 6 days ago) - Provides a development tool that gives detailed information about the execution of any request
- symfony/console (v8.1.8, 6 days ago) - Eases the creation of beautiful and testable command line interfaces
- symfony/ai (v0.14.1, 1 week ago) - Symfony AI is a set of components that integrate AI capabilities into PHP applications











