Actions
Sub-Task #239
openEpic #3: Implement a secure user authentication system
Feature #160: User Login
User Story #237: As a user, I want to log in using a security key (WebAuthn), so that I can use phishing-resistant MFA
Generate WebAuthn registration challenge and verify attestation (backend)
Sub-Task #239:
Generate WebAuthn registration challenge and verify attestation (backend)
Start date:
09/06/2026
Due date:
% Done:
100%
Estimated time:
Description
When a user adds a security key from their profile, the system issues a one-time registration challenge, then verifies the key's response before accepting it.
Behavior:
- Challenge is single-use and expires after a short delay
- Only a genuine, supported security key can produce a valid response — a replayed or forged response is rejected
- On success, the key is enrolled and immediately usable at next login
- On failure (expired challenge, invalid response, unsupported key), registration is rejected with a clear reason, existing keys are unaffected
- A user cannot register the same physical key twice on the same account
Updated by Bricklou about 1 month ago
- Description updated (diff)
Updated by Bricklou about 1 month ago
- Status changed from Draft to To Do
Updated by Bricklou about 1 month ago
- Status changed from To Do to Planned
- Assigned To set to Bricklou
- Target version set to Server 0.1.0
- Start date deleted (
08/12/2026)
Updated by Anonymous about 1 month ago
Commit referenced this issue: @1d4cac55@
https://codeberg.org/Bricklou/kubestro/commit/1d4cac552a8d696b5e9723b3b3184a08bff465ad
feat(webauthn): implement security key registration (#239, #241, #242)
Updated by Bricklou about 1 month ago
- Status changed from Planned to In Progress
- Start date set to 09/06/2026
Updated by Bricklou about 1 month ago
- Status changed from In Progress to In Review
- % Done changed from 0 to 100
Updated by Bricklou about 1 month ago
- Status changed from In Review to Done
Actions