User Story #237
openEpic #3: Implement a secure user authentication system
Feature #160: User Login
As a user, I want to log in using a security key (WebAuthn), so that I can use phishing-resistant MFA
100%
Description
As a user, I want to log in using a security key (WebAuthn/passkey), so that I can use phishing-resistant MFA.
Security keys are one of several MFA methods a user can enroll (alongside TOTP). Used strictly as a second factor, after password — not a passwordless/usernameless login (that is a separate future story).
Acceptance:
- User can register one or more security keys from their profile, each given a name by the user
- User can view their registered keys (name, date added, last used) and revoke any of them individually
- At the MFA step of login, if a user has a security key enrolled, they can use it to complete sign-in; if they have more than one MFA method enrolled, they choose which to use
- Login flow handles cancellation, no matching key present, and unsupported browser gracefully, with a clear message and a way to fall back to another enrolled method
- Existing TOTP recovery codes remain the single recovery path if a user loses access to their key(s)
- A cloned/duplicated authenticator is detected and rejected on sign-in
Updated by Bricklou about 2 months ago
- Subtask #239 added
Updated by Bricklou about 2 months ago
- Subtask #240 added
Updated by Bricklou about 2 months ago
- Subtask #241 added
Updated by Bricklou about 2 months ago
- Subtask #242 added
Updated by Bricklou about 2 months ago
- Subtask #243 added
Updated by Bricklou about 2 months ago
- Subtask #246 added
Updated by Bricklou about 2 months ago
- Subtask deleted (
#246)
Updated by Bricklou about 2 months ago
- Blocked by Feature #251: Dashboard shell & navigation added
Updated by Bricklou about 1 month ago
- Status changed from Draft to To Do
Updated by Bricklou about 1 month ago
- Status changed from To Do to Planned
- Assigned To set to Bricklou
- Target version set to Server 0.1.0
- Start date deleted (
08/12/2026)
Updated by Bricklou about 1 month ago
- Description updated (diff)
Updated by Bricklou about 1 month ago
- Subject changed from As a user, I want to log in using a security key (WebAuthn/passkey), so that I can use phishing-resistant MFA to As a user, I want to log in using a security key (WebAuthn), so that I can use phishing-resistant MFA
Updated by Anonymous about 1 month ago
Commit referenced this issue: @210@
https://codeberg.org/api/v1/repos/Bricklou/kubestro/pulls/27
closes #237
Updated by Anonymous about 1 month ago
Commit referenced this issue: @210@
https://codeberg.org/api/v1/repos/Bricklou/kubestro/pulls/27
closes #237
Updated by Anonymous about 1 month ago
Commit referenced this issue: @210@
https://codeberg.org/api/v1/repos/Bricklou/kubestro/pulls/27
closes #237
Updated by Bricklou about 1 month ago
- Status changed from Planned to In Progress
Updated by Bricklou about 1 month ago
- Status changed from In Progress to In Review
Updated by Anonymous about 1 month ago
Commit referenced this issue: @210@
https://codeberg.org/api/v1/repos/Bricklou/kubestro/pulls/27
closes #237
Updated by Anonymous about 1 month ago
Commit referenced this issue: @210@
https://codeberg.org/api/v1/repos/Bricklou/kubestro/pulls/27
closes #237
Updated by Anonymous about 1 month ago
Commit referenced this issue: @210@
https://codeberg.org/api/v1/repos/Bricklou/kubestro/pulls/27
closes #237
Updated by Anonymous about 1 month ago
Commit referenced this issue: @210@
https://codeberg.org/api/v1/repos/Bricklou/kubestro/pulls/27
closes #237
Updated by Anonymous about 1 month ago
Commit referenced this issue: @7edd3d52@
https://codeberg.org/Bricklou/kubestro/commit/7edd3d523999b5b5746387c1c499382b050794c7
feat(server): implement webauthn support (!27)
Updated by Bricklou about 1 month ago
- Status changed from In Review to Done