Sub-Task #240
Updated by Bricklou about 1 month ago
When a user with a registered security key reaches the MFA step of login, the system issues a challenge scoped to their enrolled key(s) and verifies the signed response.
Behavior:
- Challenge only accepts a response from one of that user's own enrolled keys
- Challenge is single-use and expires after a short delay
- A response reused or replayed from a previous login is rejected
- Each successful use updates that key's "last used" info
- A response indicating the key was cloned/duplicated is rejected and the key is flagged (surfaced to the user, e.g. in the settings key list) for user review
- Failure (expired challenge, wrong key, invalid response) returns a clear reason and lets the user retry or pick another enrolled MFA method
- Repeated failures are rate-limited consistently with the existing MFA lockout behavior