Project

General

Profile

Actions

Sub-Task #243

open

Epic #3: Implement a secure user authentication system

Feature #160: User Login

User Story #237: As a user, I want to log in using a security key (WebAuthn), so that I can use phishing-resistant MFA

Frontend: WebAuthn assertion flow in MFA login step

Sub-Task #243: Frontend: WebAuthn assertion flow in MFA login step

Added by Bricklou about 2 months ago. Updated about 1 month ago.

Status:
Done
Priority:
Normal
Assigned To:
Target version:
Start date:
09/06/2026
Due date:
% Done:

100%

Estimated time:

Description

Extend the MFA step of login to support signing in with a registered security key.

Behavior:

  • If the user has exactly one MFA method enrolled, that method is used directly (as today)
  • If the user has more than one MFA method enrolled (e.g. TOTP + security key), they can pick which one to use
  • Choosing security key prompts the browser/OS ceremony; on success, login completes
  • Handles and clearly messages: user cancels the prompt, browser/device doesn't support security keys, no matching key, ceremony fails or times out — with an option to switch to another enrolled method
  • "Cancel" returns to the method choice (or to the start of login), consistent with existing MFA cancel behavior
Actions

Also available in: PDF Atom