Project

General

Profile

Actions

Sub-Task #242

open

Epic #3: Implement a secure user authentication system

Feature #160: User Login

User Story #237: As a user, I want to log in using a security key (WebAuthn), so that I can use phishing-resistant MFA

Frontend: WebAuthn credential registration flow in user profile

Sub-Task #242: Frontend: WebAuthn credential registration flow in user profile

Added by Bricklou about 2 months ago. Updated about 1 month ago.

Status:
Done
Priority:
Normal
Assigned To:
Target version:
Start date:
09/06/2026
Due date:
% Done:

100%

Estimated time:

Description

Add a "Security keys" section to account security settings, alongside existing TOTP settings.

Behavior:

  • Shows the list of registered keys: name, date added, last used
  • "Add a security key" starts registration: prompts the browser/OS security key ceremony, then asks the user to name the key, then confirms it's added
  • Handles and clearly messages: user cancels the prompt, browser/device doesn't support security keys, ceremony fails or times out
  • Each listed key can be renamed and revoked (with confirmation) independently
  • This section is additive to TOTP — a user can have both enabled at once
Actions

Also available in: PDF Atom