fix(passkey): serve flat WebAuthn options to register and username login
go-webauthn marshals CredentialCreation/CredentialAssertion as {"publicKey": {...}},
but the panel's register (Account.tsx) and username-first login (Login.tsx) read the
options flat (options.challenge, options.user.id), so base64urlToBytes(undefined) threw
"Cannot read properties of undefined (reading 'replace')" and neither ceremony could
start. Strip the envelope in the register-begin and username-login-begin handlers via a
small unwrapPublicKey helper; discoverable login keeps the envelope because it reads
options.publicKey.* plus a top-level options.login_id. The begin tests now feed a wrapped
body and assert the handlers return it flat, so they genuinely exercise the unwrap.
This commit is contained in:
3 files changed
+30
-11
No files matched your search
@@ -77,15 +77,15 @@ func TestPasskeyLoginVertical(t *testing.T) {
|
||||
api, repo, v := seedLoginPasskeyAPI(t)
|
||||
eh := api.ExternalHandler()
|
||||
|
||||
// 1) begin: options verbatim, exactly one login-purpose challenge stashed for u1, and
|
||||
// 1) begin: options FLAT (envelope stripped), exactly one login-purpose challenge stashed for u1, and
|
||||
// the account's bound credential handed to the verifier (so the authenticator can be
|
||||
// asked to assert with a known key).
|
||||
w := do(eh, "POST", "/api/v1/auth/passkey/login/begin", `{"email":"[email protected]"}`, jsonHeader)
|
||||
if w.Code != http.StatusOK {
|
||||
t.Fatalf("begin: code = %d, want 200 (%s)", w.Code, w.Body.String())
|
||||
}
|
||||
if b := acctBody(t, w); b["publicKey"] == nil {
|
||||
t.Errorf("begin must return the assertion options verbatim, got %s", w.Body.String())
|
||||
if b := acctBody(t, w); b["challenge"] == nil || b["publicKey"] != nil {
|
||||
t.Errorf("begin must return FLAT assertion options (top-level challenge, no publicKey envelope), got %s", w.Body.String())
|
||||
}
|
||||
if v.lastUser.ID != "u1" {
|
||||
t.Errorf("begin passed user id %q, want u1", v.lastUser.ID)
|
||||
|
||||
Reference in new issue
Block a user