Actions
Sub-Task #242
openEpic #3: Implement a secure user authentication system
Feature #160: User Login
User Story #237: As a user, I want to log in using a security key (WebAuthn), so that I can use phishing-resistant MFA
Frontend: WebAuthn credential registration flow in user profile
Sub-Task #242:
Frontend: WebAuthn credential registration flow in user profile
Start date:
09/06/2026
Due date:
% Done:
100%
Estimated time:
Description
Add a "Security keys" section to account security settings, alongside existing TOTP settings.
Behavior:
- Shows the list of registered keys: name, date added, last used
- "Add a security key" starts registration: prompts the browser/OS security key ceremony, then asks the user to name the key, then confirms it's added
- Handles and clearly messages: user cancels the prompt, browser/device doesn't support security keys, ceremony fails or times out
- Each listed key can be renamed and revoked (with confirmation) independently
- This section is additive to TOTP — a user can have both enabled at once
Actions