My name is Florent Morselli (flɔʁɑ̃ mɔʁseli). I am a French web developer and project manager passionate about PHP, ReactJS and Free, Libre & Open-Source Software. As far as possible, I contribute to projects or publish my own work.
🧡 Since early 2025, I am proud to be a
. This allows me to help shape the future of the framework I use and love daily.
The projects I am working on are mainly related to security over web applications. In particular, you will find useful libraries of Symfony bundles for
- One-Time Passwords (TOTP/HOTP) => see https://github.com/Spomky-Labs/otphp,
- Json Web Tokens (JWT, including signed and encrypted ones) => see https://github.com/web-token,
- Web Push => see https://github.com/Spomky-Labs/web-push,
- Concise Binary Object Representation (CBOR) => see https://github.com/Spomky-Labs/cbor-php,
- Webauthn => see https://github.com/web-auth.
Among all of these projects, let me encourage you to read more about Webauthn, a PHP implementation I am working on since end of 2018 and that will help you to get rid of passwords.
In addition, I had the opportunity to share my knowledge during the following events:
- September 2022: I presented the possibilities offered by this technology during the second edition of ApiPlatformCon in September 2022 in Lille, France.
- March 2023, I gave two 1-day workshops during the Symfony Live Paris 2023.
- December 2023, I gave a 1-day workshop during the Symfony Con Brussels 2023.
- March 2024, I presented my feedback on the Progressive Web Apps and gave a 1-day workshop during the Symfony Live 2024.
- March 2025, I gave a 1-day workshop during the Symfony Live 2025
Feel free to ask me about all of these FLOSS projects or reach me on any other topics you may want to discuss.
Hereafter an overview of my involvement in the Open-Source ecosystem. If you wish, you can sponsor me. The GitHub Sponsors page or the Patreon page are made for that purpose. Any help is greatly appreciated and allows me to spend time on these projects.
- Spomky-Labs/cbor-php - CBOR Encoder/Decoder for PHP (today)
- web-auth/cose-lib - Cose Key and Algorithms support (2 days ago)
- web-token/jwt-framework - JWT Framework (2 days ago)
- Spomky-Labs/cbor-bundle - CBOR Encoder/Decoder Bundle for Symfony (3 days ago)
- Spomky-Labs/pki-framework - Public Key Infrastructure (3 days ago)
- leo-gan/GLD.SerializerBenchmark - Serialization benchmarks (13 languages, 200+ codecs), Compliance tests, Serialization 101–401 course (3 days ago)
- web-auth/webauthn-framework - FIDO-U2F / FIDO2 / Webauthn Framework (5 days ago)
- Spomky-Labs/web-push - This framework contains PHP libraries and Symfony bundle to allow developers to integrate web-push notifications into their web applications. (1 week ago)
- symfony/security-bundle - Provides a tight integration of the Security component into the Symfony full-stack framework (1 week ago)
- symfony/security-http - Symfony Security Component - HTTP Integration (1 week ago)
- fix(composer): stop replacing symfony/polyfill-php81 on web-auth/cose-lib (today)
- php: compliance runner compares the normalized CBOR value, not the object model on leo-gan/GLD.SerializerBenchmark (today)
- fix(map): keep every key RFC 8949 allows instead of rejecting the map on Spomky-Labs/cbor-php (today)
- feat(diagnostic): diagnostic notation (RFC 8949 §8), annotated with the CDDL of a schema on Spomky-Labs/cbor-php (2 days ago)
- feat(tag): COSE_Countersignature tag 19 (RFC 9338 §3.1) on Spomky-Labs/cbor-php (2 days ago)
- feat(headers): 3161-ttc and 3161-ctt timestamp tokens, carried and bound, not validated (RFC 9921) (#217) on web-auth/cose-lib (2 days ago)
- docs: ES256K moves from the experimental table to the standard one (RFC 8812) on web-token/jwt-doc (2 days ago)
- feat(signature): move ES256K from the experimental package to the library (RFC 8812) on web-token/jwt-framework (2 days ago)
- docs: document ML-DSA and the AKP key type (RFC 9964) on web-token/jwt-doc (2 days ago)
- feat(signature): ML-DSA-44/65/87 and the AKP key type via OpenSSL 3.5 (RFC 9964) on web-token/jwt-framework (2 days ago)
- api-platform/core (v5.0.0-beta.2, today) - The server component of API Platform: hypermedia and GraphQL APIs in minutes
- symfony/symfony (v8.1.7, today) - The Symfony PHP framework
- symfony/validator (v8.1.7, today) - Provides tools to validate values
- symfony/framework-bundle (v8.1.7, today) - Provides a tight integration between Symfony components and the Symfony full-stack framework
- symfony/console (v8.1.7, today) - Eases the creation of beautiful and testable command line interfaces
- symfony/security-bundle (v8.1.7, today) - Provides a tight integration of the Security component into the Symfony full-stack framework
- symfony/security-http (v8.1.7, today) - Symfony Security Component - HTTP Integration
- symfony/web-profiler-bundle (v8.1.7, today) - Provides a development tool that gives detailed information about the execution of any request
- symfony/mailer (v8.1.7, today) - Helps sending emails
- symfony/mime (v8.1.7, today) - Allows manipulating MIME messages












