Actions
Sub-Task #243
openEpic #3: Implement a secure user authentication system
Feature #160: User Login
User Story #237: As a user, I want to log in using a security key (WebAuthn), so that I can use phishing-resistant MFA
Frontend: WebAuthn assertion flow in MFA login step
Sub-Task #243:
Frontend: WebAuthn assertion flow in MFA login step
Start date:
09/06/2026
Due date:
% Done:
100%
Estimated time:
Description
Extend the MFA step of login to support signing in with a registered security key.
Behavior:
- If the user has exactly one MFA method enrolled, that method is used directly (as today)
- If the user has more than one MFA method enrolled (e.g. TOTP + security key), they can pick which one to use
- Choosing security key prompts the browser/OS ceremony; on success, login completes
- Handles and clearly messages: user cancels the prompt, browser/device doesn't support security keys, no matching key, ceremony fails or times out — with an option to switch to another enrolled method
- "Cancel" returns to the method choice (or to the start of login), consistent with existing MFA cancel behavior
Updated by Bricklou about 1 month ago
- Description updated (diff)
Updated by Bricklou about 1 month ago
- Status changed from Draft to To Do
Updated by Bricklou about 1 month ago
- Status changed from To Do to Planned
- Assigned To set to Bricklou
- Target version set to Server 0.1.0
- Start date deleted (
08/12/2026)
Updated by Bricklou about 1 month ago
- Status changed from Planned to In Progress
- Start date set to 09/06/2026
Updated by Anonymous about 1 month ago
Commit referenced this issue: @4e56be0c@
https://codeberg.org/Bricklou/kubestro/commit/4e56be0cba76d5a94e2ff2c8cbcc1f949ac1456f
feat(webauthn): implement security key authentication at login (#240, #243)
Updated by Bricklou about 1 month ago
- Status changed from In Progress to In Review
- % Done changed from 0 to 100
Updated by Bricklou about 1 month ago
- Status changed from In Review to Done
Actions