feat(passkey): require and record user verification at enrollment
Enrollment set no AuthenticatorSelection, so user verification defaulted to preferred (not enforced), and the UV/backup flags the ceremony reported were discarded. Set UserVerification=required so a bound passkey always proves possession AND user (a UV-incapable device falls back to email-OTP), and capture user_verified/backup_eligible/backup_state through VerifiedCredential -> PasskeyCredential -> webauthn_credentials (migration 0009) so a future login path can enforce UV per credential. Adds a negative test proving a presence-only authenticator is rejected, and asserts the roundtrip records UV=true.
This commit is contained in:
6 files changed
+109
-13
No files matched your search
@@ -107,6 +107,13 @@ type PasskeyCredential struct {
|
||||
Name string
|
||||
CreatedAt time.Time
|
||||
LastUsedAt *time.Time
|
||||
// Ceremony flags captured at enrollment (migration 0009). UserVerified records that a
|
||||
// PIN/biometric was performed at bind; BackupEligible/BackupState record whether the
|
||||
// credential is syncable/backed up. Persisted so a future login path can enforce UV
|
||||
// per credential and reason about single-device vs. synced authenticators.
|
||||
UserVerified bool
|
||||
BackupEligible bool
|
||||
BackupState bool
|
||||
}
|
||||
|
||||
// SessionedUser is the projection resolved from a live session cookie: the
|
||||
|
||||
Reference in new issue
Block a user