Project

General

Profile

Sub-Task #239

Updated by Bricklou about 1 month ago

When a user adds a security key from their profile, the system issues a one-time registration challenge, then verifies the key's response before accepting it. 

 Behavior: 
 - Challenge is single-use and expires after a short delay 
 - Only a genuine, supported security key can produce a valid response — a replayed or forged response is rejected 
 - On success, the key is enrolled and immediately usable at next login 
 - On failure (expired challenge, invalid response, unsupported key), registration is rejected with a clear reason, existing keys are unaffected 
 - A user cannot register the same physical key twice on the same account

Back