Project

General

Profile

Sub-Task #240

Updated by Bricklou about 1 month ago

When a user with a registered security key reaches the MFA step of login, the system issues a challenge scoped to their enrolled key(s) and verifies the signed response. 

 Behavior: 
 - Challenge only accepts a response from one of that user's own enrolled keys 
 - Challenge is single-use and expires after a short delay 
 - A response reused or replayed from a previous login is rejected 
 - Each successful use updates that key's "last used" info 
 - A response indicating the key was cloned/duplicated is rejected and the key is flagged (surfaced to the user, e.g. in the settings key list) for user review 
 - Failure (expired challenge, wrong key, invalid response) returns a clear reason and lets the user retry or pick another enrolled MFA method 
 - Repeated failures are rate-limited consistently with the existing MFA lockout behavior

Back