Skip to content

[6.x] Register passkeys as discoverable credentials - #15491

Merged
jasonvarga merged 1 commit into
6.xfrom
fix-15489
Sep 21, 2026
Merged

jasonvarga merged 1 commit into
6.xfrom
fix-15489

Conversation

@duncanmcclean

@duncanmcclean duncanmcclean commented Sep 21, 2026 •

Copy link
Copy Markdown
Member

This pull request fixes an issue where passkeys registered with some password managers (Bitwarden, for example) couldn't be used to sign in. Registration succeeded and the passkey appeared in the list, but the authenticator reported it had no passkey for the site at login.

This was happening because the creation options never set authenticatorSelection, so residentKey was left unspecified and treated as discouraged. Authenticators that honour that hint (Bitwarden, hardware keys) create a non-discoverable credential, which our sign-in flow can never find since it sends no allowCredentials and resolves the user from the returned userHandle. Platform authenticators like Windows Hello, iCloud Keychain and 1Password always create discoverable credentials regardless, which is why this hadn't surfaced sooner.

This PR fixes it by requiring a discoverable credential (residentKey: required) and user verification when registering a passkey. User verification was already required at login, so requiring it at registration means an authenticator that can't verify the user fails early rather than at sign-in.

Existing passkeys that already work are unaffected. Passkeys that were affected by this bug (ones that never worked at login) will need to be deleted and re-added.

Fixes #15489

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@jasonvarga
jasonvarga merged commit be83668 into 6.x Sep 21, 2026
66 checks passed
@jasonvarga
jasonvarga deleted the fix-15489 branch September 21, 2026 17:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Passkeys are registered as non-discoverable credentials, so passkey sign-in can never find them

2 participants