+6
−0
+146
−0
+53
−0
+58
−0
Loading
Phase 6 WebAuthn bind, enrollment-only slice (spec section 14). Adds the data layer an already-authenticated principal needs to bind and manage passkeys: - migration 0007: webauthn_credentials (one bound passkey per row, public attestation material only) and webauthn_challenges (server-stashed ceremony state between begin and finish, single-use via consumed_at). Both rows are bound to a known user_id; there is no usernameless login lookup, since the assertion/login path is a deferred slice. - PasskeyCredential type and five Repo methods (create/consume challenge, create/list/delete credential) with the PG semantics the handlers rely on: supersede-prior-live on begin, expiry-before-consume single-use on finish, credential_id UNIQUE -> ErrConflict, owner-scoped delete -> ErrNotFound. - ErrPasskeyChallengeInvalid sentinel for a missing/expired/consumed ceremony.