Sub-Task #239
Updated by Bricklou about 1 month ago
When a user adds a security key from their profile, the system issues a one-time registration challenge, then verifies the key's response before accepting it.
Behavior:
- Challenge is single-use and expires after a short delay
- Only a genuine, supported security key can produce a valid response — a replayed or forged response is rejected
- On success, the key is enrolled and immediately usable at next login
- On failure (expired challenge, invalid response, unsupported key), registration is rejected with a clear reason, existing keys are unaffected
- A user cannot register the same physical key twice on the same account