fix(passkey): 断言时按凭据校验 UV,并把存储的 BE/BS 标志交给校验器,云同步 passkey 可以登录 (#9)

This commit is contained in:
Lemon-miaow committed 2026-09-26 07:12:20 +08:00
1 parent 6a4c30b3f1
commit 9ab7b27a30
13 files changed
+319 -96

No files matched your search

+6 -7
View File
@@ -329,13 +329,12 @@ func (a *API) finishStepUpPasskey(w http.ResponseWriter, r *http.Request, p *Pri
a.authFailure(r, door, "bad_assertion", nil)
return invalid()
}
// Same clone policy as the login door (applyAssertionCounter): a rolled-back
// counter fails closed with the opaque envelope, so a step-up never accepts an
// authenticator that login refuses. A clean assertion advances the stored
// sign-count, keeping the clone signal meaningful for the next login.
if err := a.applyAssertionCounter(r.Context(), va); err != nil {
if errors.Is(err, errPasskeyClonedAuthenticator) {
a.passkeyCloneRejected(r, door, nil, va.CredentialID)
// Same UV and clone policy as the login door (applyAssertion): an unverified
// user or a rolled-back counter fails closed with the opaque envelope, so a
// step-up never accepts an authenticator that login refuses. A clean assertion
// advances the stored sign-count, keeping the clone signal meaningful.
if err := a.applyAssertion(r.Context(), va, creds); err != nil {
if a.passkeyAssertionRejected(r, door, nil, va.CredentialID, err) {
return invalid()
}
writeError(w, r, err)