feat(passkey): require and record user verification at enrollment

Enrollment set no AuthenticatorSelection, so user verification defaulted to preferred (not enforced), and the UV/backup flags the ceremony reported were discarded. Set UserVerification=required so a bound passkey always proves possession AND user (a UV-incapable device falls back to email-OTP), and capture user_verified/backup_eligible/backup_state through VerifiedCredential -> PasskeyCredential -> webauthn_credentials (migration 0009) so a future login path can enforce UV per credential. Adds a negative test proving a presence-only authenticator is rejected, and asserts the roundtrip records UV=true.
This commit is contained in:
flyemoji committed 2026-07-02 06:55:21 +09:00
1 parent 20e31fb08f
commit 7278cd7c6a
6 files changed
+109 -13

No files matched your search

+7
View File
@@ -107,6 +107,13 @@ type PasskeyCredential struct {
Name string
CreatedAt time.Time
LastUsedAt *time.Time
// Ceremony flags captured at enrollment (migration 0009). UserVerified records that a
// PIN/biometric was performed at bind; BackupEligible/BackupState record whether the
// credential is syncable/backed up. Persisted so a future login path can enforce UV
// per credential and reason about single-device vs. synced authenticators.
UserVerified bool
BackupEligible bool
BackupState bool
}
// SessionedUser is the projection resolved from a live session cookie: the