Project

General

Profile

Actions

Sub-Task #239

open

Epic #3: Implement a secure user authentication system

Feature #160: User Login

User Story #237: As a user, I want to log in using a security key (WebAuthn), so that I can use phishing-resistant MFA

Generate WebAuthn registration challenge and verify attestation (backend)

Sub-Task #239: Generate WebAuthn registration challenge and verify attestation (backend)

Added by Bricklou about 2 months ago. Updated 16 days ago.

Status:
Done
Priority:
Normal
Assigned To:
Target version:
Start date:
09/06/2026
Due date:
% Done:

100%

Estimated time:

Description

When a user adds a security key from their profile, the system issues a one-time registration challenge, then verifies the key's response before accepting it.

Behavior:

  • Challenge is single-use and expires after a short delay
  • Only a genuine, supported security key can produce a valid response — a replayed or forged response is rejected
  • On success, the key is enrolled and immediately usable at next login
  • On failure (expired challenge, invalid response, unsupported key), registration is rejected with a clear reason, existing keys are unaffected
  • A user cannot register the same physical key twice on the same account
Actions

Also available in: PDF Atom