Project

General

Profile

Actions

Sub-Task #240

open

Epic #3: Implement a secure user authentication system

Feature #160: User Login

User Story #237: As a user, I want to log in using a security key (WebAuthn), so that I can use phishing-resistant MFA

Generate WebAuthn authentication challenge and verify assertion (backend)

Sub-Task #240: Generate WebAuthn authentication challenge and verify assertion (backend)

Added by Bricklou about 2 months ago. Updated about 1 month ago.

Status:
Done
Priority:
Normal
Assigned To:
Target version:
Start date:
09/06/2026
Due date:
% Done:

100%

Estimated time:

Description

When a user with a registered security key reaches the MFA step of login, the system issues a challenge scoped to their enrolled key(s) and verifies the signed response.

Behavior:

  • Challenge only accepts a response from one of that user's own enrolled keys
  • Challenge is single-use and expires after a short delay
  • A response reused or replayed from a previous login is rejected
  • Each successful use updates that key's "last used" info
  • A response indicating the key was cloned/duplicated is rejected and the key is flagged (surfaced to the user, e.g. in the settings key list) for user review
  • Failure (expired challenge, wrong key, invalid response) returns a clear reason and lets the user retry or pick another enrolled MFA method
  • Repeated failures are rate-limited consistently with the existing MFA lockout behavior

Updated by Bricklou about 1 month ago Author Actions #1

  • Description updated (diff)

Updated by Bricklou about 1 month ago Author Actions #2

  • Status changed from Draft to To Do

Updated by Bricklou about 1 month ago Author Actions #3

  • Status changed from To Do to Planned
  • Assigned To set to Bricklou
  • Target version set to Server 0.1.0
  • Start date deleted (08/12/2026)

Updated by Bricklou about 1 month ago Author Actions #4

  • Status changed from Planned to In Progress
  • Start date set to 09/06/2026

Updated by Anonymous about 1 month ago Actions #5

Commit referenced this issue: @4e56be0c@

https://codeberg.org/Bricklou/kubestro/commit/4e56be0cba76d5a94e2ff2c8cbcc1f949ac1456f

feat(webauthn): implement security key authentication at login (#240, #243)

Updated by Bricklou about 1 month ago Author Actions #6

  • Status changed from In Progress to In Review
  • % Done changed from 0 to 100

Updated by Bricklou about 1 month ago Author Actions #7

  • Status changed from In Review to Done
Actions

Also available in: PDF Atom