mirror of
https://github.com/fluxerapp/fluxer
synced 2026-10-07 19:22:14 +09:00
fix(auth): offer every transport for passkeys stored without any (#3077)
This commit is contained in:
@@ -168,12 +168,17 @@ export async function verifyMfaCode(ctx: ApiContext, params: VerifyMfaCodeParams
|
||||
return false;
|
||||
}
|
||||
|
||||
type CredentialTransport = 'usb' | 'nfc' | 'ble' | 'internal' | 'cable' | 'hybrid';
|
||||
|
||||
const ALL_CREDENTIAL_TRANSPORTS: Array<CredentialTransport> = ['internal', 'hybrid', 'usb', 'nfc', 'ble'];
|
||||
|
||||
function toCredentialDescriptor(credential: WebAuthnCredential) {
|
||||
return {
|
||||
id: credential.credentialId,
|
||||
transports: credential.transports
|
||||
? (Array.from(credential.transports) as Array<'usb' | 'nfc' | 'ble' | 'internal' | 'cable' | 'hybrid'>)
|
||||
: undefined,
|
||||
transports:
|
||||
credential.transports && credential.transports.size > 0
|
||||
? (Array.from(credential.transports) as Array<CredentialTransport>)
|
||||
: ALL_CREDENTIAL_TRANSPORTS,
|
||||
};
|
||||
}
|
||||
|
||||
|
||||
@@ -65,6 +65,7 @@ describe('WebAuthn MFA login', () => {
|
||||
expect(mfaOptions.userVerification).toBe('discouraged');
|
||||
expect(mfaOptions.allowCredentials).toBeTruthy();
|
||||
expect(mfaOptions.allowCredentials!.length).toBeGreaterThan(0);
|
||||
expect(mfaOptions.allowCredentials![0]!.transports).toEqual(['internal']);
|
||||
if (mfaOptions.rpId) {
|
||||
device.rpId = mfaOptions.rpId;
|
||||
}
|
||||
@@ -87,6 +88,48 @@ describe('WebAuthn MFA login', () => {
|
||||
.execute();
|
||||
expect(userInfo.id).toBe(account.userId);
|
||||
});
|
||||
it('offers every transport for a passkey registered without transports', async () => {
|
||||
const account = await createTestAccount(harness);
|
||||
const device = createWebAuthnDevice();
|
||||
device.transports = null;
|
||||
const secret = createTotpSecret();
|
||||
await createBuilder(harness, account.token)
|
||||
.post('/users/@me/mfa/totp/enable')
|
||||
.body({secret, code: generateTotpCode(secret), password: account.password})
|
||||
.execute();
|
||||
await registerWebAuthnCredential(harness, account.token, device, () => ({
|
||||
mfa_method: 'totp',
|
||||
mfa_code: generateTotpCode(secret),
|
||||
}));
|
||||
await setWebAuthnTwoFactor(harness, account.token, true, {
|
||||
mfa_method: 'totp',
|
||||
mfa_code: generateTotpCode(secret),
|
||||
});
|
||||
const loginResp = (await loginUser(harness, {
|
||||
email: account.email,
|
||||
password: account.password,
|
||||
})) as LoginMfaResponse;
|
||||
const mfaOptions = await createBuilderWithoutAuth<WebAuthnAuthenticationOptions>(harness)
|
||||
.post('/auth/login/mfa/webauthn/authentication-options')
|
||||
.body({ticket: loginResp.ticket})
|
||||
.execute();
|
||||
expect(mfaOptions.allowCredentials).toEqual([
|
||||
{
|
||||
id: device.credentialId.toString('base64url'),
|
||||
type: 'public-key',
|
||||
transports: ['internal', 'hybrid', 'usb', 'nfc', 'ble'],
|
||||
},
|
||||
]);
|
||||
const webauthnMfaLogin = await createBuilderWithoutAuth<{token: string}>(harness)
|
||||
.post('/auth/login/mfa/webauthn')
|
||||
.body({
|
||||
response: createAuthenticationResponse(device, mfaOptions),
|
||||
challenge: mfaOptions.challenge,
|
||||
ticket: loginResp.ticket,
|
||||
})
|
||||
.execute();
|
||||
expect(webauthnMfaLogin.token).toBeTruthy();
|
||||
});
|
||||
it('issues a session token instead of an MFA ticket when passkey two-factor is left off', async () => {
|
||||
const account = await createTestAccount(harness);
|
||||
const device = createWebAuthnDevice();
|
||||
|
||||
@@ -21,6 +21,7 @@ export interface WebAuthnDevice {
|
||||
rpId: string;
|
||||
origin: string;
|
||||
signCount: number;
|
||||
transports?: Array<string> | null;
|
||||
}
|
||||
|
||||
export interface WebAuthnRegistrationOptions {
|
||||
@@ -47,6 +48,7 @@ export interface WebAuthnAuthenticationOptions {
|
||||
allowCredentials?: Array<{
|
||||
id: string;
|
||||
type: string;
|
||||
transports?: Array<string>;
|
||||
}>;
|
||||
userVerification: string;
|
||||
}
|
||||
@@ -75,7 +77,7 @@ export interface WebAuthnTwoFactorResult {
|
||||
interface AuthenticatorAttestationResponse {
|
||||
clientDataJSON: string;
|
||||
attestationObject: string;
|
||||
transports: Array<string>;
|
||||
transports?: Array<string>;
|
||||
}
|
||||
|
||||
interface AuthenticatorAssertionResponse {
|
||||
@@ -363,7 +365,7 @@ export function createRegistrationResponse(
|
||||
response: {
|
||||
clientDataJSON: encodeBase64URL(clientDataJSON),
|
||||
attestationObject: encodeBase64URL(attestationObject),
|
||||
transports: ['internal'],
|
||||
...(device.transports === null ? {} : {transports: device.transports ?? ['internal']}),
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user