Project

General

Profile

Sub-Task #241

Updated by Bricklou about 1 month ago

Store what's needed to recognize and trust each registered security key, per user. 

 Data kept per key: owning user, user-chosen name, public key, credential identifier, current sign counter, date added, last used date, revoked state. 

 Behavior: 
 - A user can have zero, one, or several keys 
 - Revoking a key immediately makes it unusable for login without deleting its history (name/dates remain visible until fully removed if the UX calls for it — otherwise a straight delete is fine) 
 - No secret/private key material is ever stored (WebAuthn keeps that on the user's device) — only what's needed to verify future logins 
 - Sign counter is updated on every successful login use, and a decrease/repeat is treated as a cloning signal (see #240)

Back