026120497913ee577860419d76e4e85497dc406a
Wrap github.com/go-webauthn/webauthn behind the api.PasskeyVerifier seam so the api package stays free of go-webauthn types. The adapter covers the credential-creation ceremony only (BeginRegistration / CreateCredential); the login/assertion path is a deferred slice. Ceremony state crosses the seam as opaque marshaled SessionData, the attestation as an io.Reader, and the verified result as a plain VerifiedCredential. SessionData carries no expiry so the challenge row's TTL stays the single liveness authority. New rejects an empty RP id or origin list so a misconfigured deployment fails at construction rather than minting unverifiable challenges. Tests drive a real relying party against a virtual authenticator (descope/virtualwebauthn): a full creation round-trip plus adversarial guards proving origin-mismatch and user-mismatch are rejected and already-bound credentials are excluded.
Languages
Go
62.7%
TypeScript
22.5%
Shell
7.4%
Java
7.1%
Dockerfile
0.2%
Other
0.1%