f2c916d3785a979227c25acb1c5e0d57a38d2472
Phase 6 WebAuthn bind, enrollment-only slice (spec section 14). Adds the data layer an already-authenticated principal needs to bind and manage passkeys: - migration 0007: webauthn_credentials (one bound passkey per row, public attestation material only) and webauthn_challenges (server-stashed ceremony state between begin and finish, single-use via consumed_at). Both rows are bound to a known user_id; there is no usernameless login lookup, since the assertion/login path is a deferred slice. - PasskeyCredential type and five Repo methods (create/consume challenge, create/list/delete credential) with the PG semantics the handlers rely on: supersede-prior-live on begin, expiry-before-consume single-use on finish, credential_id UNIQUE -> ErrConflict, owner-scoped delete -> ErrNotFound. - ErrPasskeyChallengeInvalid sentinel for a missing/expired/consumed ceremony.
Languages
Go
62.7%
TypeScript
22.5%
Shell
7.4%
Java
7.1%
Dockerfile
0.2%
Other
0.1%