Actions
Sub-Task #239
openEpic #3: Implement a secure user authentication system
Feature #160: User Login
User Story #237: As a user, I want to log in using a security key (WebAuthn), so that I can use phishing-resistant MFA
Generate WebAuthn registration challenge and verify attestation (backend)
Sub-Task #239:
Generate WebAuthn registration challenge and verify attestation (backend)
Start date:
09/06/2026
Due date:
% Done:
100%
Estimated time:
Description
When a user adds a security key from their profile, the system issues a one-time registration challenge, then verifies the key's response before accepting it.
Behavior:
- Challenge is single-use and expires after a short delay
- Only a genuine, supported security key can produce a valid response — a replayed or forged response is rejected
- On success, the key is enrolled and immediately usable at next login
- On failure (expired challenge, invalid response, unsupported key), registration is rejected with a clear reason, existing keys are unaffected
- A user cannot register the same physical key twice on the same account
Actions