Project

General

Profile

Actions

Sub-Task #240

open

Epic #3: Implement a secure user authentication system

Feature #160: User Login

User Story #237: As a user, I want to log in using a security key (WebAuthn), so that I can use phishing-resistant MFA

Generate WebAuthn authentication challenge and verify assertion (backend)

Sub-Task #240: Generate WebAuthn authentication challenge and verify assertion (backend)

Added by Bricklou about 2 months ago. Updated about 1 month ago.

Status:
Done
Priority:
Normal
Assigned To:
Target version:
Start date:
09/06/2026
Due date:
% Done:

100%

Estimated time:

Description

When a user with a registered security key reaches the MFA step of login, the system issues a challenge scoped to their enrolled key(s) and verifies the signed response.

Behavior:

  • Challenge only accepts a response from one of that user's own enrolled keys
  • Challenge is single-use and expires after a short delay
  • A response reused or replayed from a previous login is rejected
  • Each successful use updates that key's "last used" info
  • A response indicating the key was cloned/duplicated is rejected and the key is flagged (surfaced to the user, e.g. in the settings key list) for user review
  • Failure (expired challenge, wrong key, invalid response) returns a clear reason and lets the user retry or pick another enrolled MFA method
  • Repeated failures are rate-limited consistently with the existing MFA lockout behavior
Actions

Also available in: PDF Atom