+22
−0
Loading
Construct the go-webauthn verifier at the composition root and attach it to the API when auth.panel_hostname is configured (RP id = panel hostname, origin = https://<panel hostname>, display name Felis). When the hostname is unset or the verifier fails to build it stays nil and the passkey ceremony routes report 503, matching the existing nil-when-unconfigured subsystem pattern. An admin passkey, if ever added, is a separate relying party on the admin host and is intentionally not wired here.