[6.x] Register passkeys as discoverable credentials - #15491
Merged
Merged
Conversation
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request fixes an issue where passkeys registered with some password managers (Bitwarden, for example) couldn't be used to sign in. Registration succeeded and the passkey appeared in the list, but the authenticator reported it had no passkey for the site at login.
This was happening because the creation options never set
authenticatorSelection, soresidentKeywas left unspecified and treated asdiscouraged. Authenticators that honour that hint (Bitwarden, hardware keys) create a non-discoverable credential, which our sign-in flow can never find since it sends noallowCredentialsand resolves the user from the returneduserHandle. Platform authenticators like Windows Hello, iCloud Keychain and 1Password always create discoverable credentials regardless, which is why this hadn't surfaced sooner.This PR fixes it by requiring a discoverable credential (
residentKey: required) and user verification when registering a passkey. User verification was already required at login, so requiring it at registration means an authenticator that can't verify the user fails early rather than at sign-in.Existing passkeys that already work are unaffected. Passkeys that were affected by this bug (ones that never worked at login) will need to be deleted and re-added.
Fixes #15489