Actions
Sub-Task #243
openEpic #3: Implement a secure user authentication system
Feature #160: User Login
User Story #237: As a user, I want to log in using a security key (WebAuthn), so that I can use phishing-resistant MFA
Frontend: WebAuthn assertion flow in MFA login step
Sub-Task #243:
Frontend: WebAuthn assertion flow in MFA login step
Start date:
09/06/2026
Due date:
% Done:
100%
Estimated time:
Description
Extend the MFA step of login to support signing in with a registered security key.
Behavior:
- If the user has exactly one MFA method enrolled, that method is used directly (as today)
- If the user has more than one MFA method enrolled (e.g. TOTP + security key), they can pick which one to use
- Choosing security key prompts the browser/OS ceremony; on success, login completes
- Handles and clearly messages: user cancels the prompt, browser/device doesn't support security keys, no matching key, ceremony fails or times out — with an option to switch to another enrolled method
- "Cancel" returns to the method choice (or to the start of login), consistent with existing MFA cancel behavior
Actions