User Story #237
Updated by Bricklou about 1 month ago
As a user, I want to log in using a This user story covers WebAuthn-based multi-factor authentication (passkeys and hardware security key (WebAuthn/passkey), so that I can use phishing-resistant MFA. keys). Security keys are one of several MFA methods a user can enroll (alongside TOTP). Used strictly as a second factor, after password — not a passwordless/usernameless login (that is a separate future story). Acceptance: Acceptance requirements: - User Users can register one or more security keys WebAuthn credentials from their profile, each given a name by the user profile - User can view their Users with a registered keys (name, date added, last used) and revoke any of them individually - At the MFA step of login, if a user has a security key enrolled, they can are prompted to use it to complete sign-in; if they have more than one during the MFA method enrolled, they choose which to use login step - Login The login flow correctly handles cancellation, no matching key present, cancellation and unsupported browser gracefully, with a clear message and a way to fall back to another enrolled method scenarios - Existing TOTP recovery codes remain Credentials are bound to the single recovery path if a user loses access to their key(s) and stored securely (public key, credential ID, sign count) - A cloned/duplicated authenticator Sign count is detected and rejected verified on sign-in each assertion to detect cloned authenticators