Project

General

Profile

User Story #237

Updated by Bricklou about 1 month ago

As a user, I want to log in using a This user story covers WebAuthn-based multi-factor authentication (passkeys and hardware security key (WebAuthn/passkey), so that I can use phishing-resistant MFA. keys). 

 Security keys are one of several MFA methods a user can enroll (alongside TOTP). Used strictly as a second factor, after password — not a passwordless/usernameless login (that is a separate future story). 

 Acceptance: Acceptance requirements: 
 - User Users can register one or more security keys WebAuthn credentials from their profile, each given a name by the user profile 
 - User can view their Users with a registered keys (name, date added, last used) and revoke any of them individually 
 - At the MFA step of login, if a user has a security key enrolled, they can are prompted to use it to complete sign-in; if they have more than one during the MFA method enrolled, they choose which to use login step 
 - Login The login flow correctly handles cancellation, no matching key present, cancellation and unsupported browser gracefully, with a clear message and a way to fall back to another enrolled method scenarios 
 - Existing TOTP recovery codes remain Credentials are bound to the single recovery path if a user loses access to their key(s) and stored securely (public key, credential ID, sign count) 
 - A cloned/duplicated authenticator Sign count is detected and rejected verified on sign-in each assertion to detect cloned authenticators

Back