Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

WebAuthn: prefer discoverable credentials with legacy fallback#57140

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Open
swissbit-eis-admin wants to merge1 commit intonextcloud:stable32
base:stable32
Choose a base branch
Loading
fromswissbit-eis:fido2-supprt-discoverable-keys

Conversation

@swissbit-eis-admin
Copy link

  • require resident keys/UV for new FIDO2 registrations, but retry without if unsupported
  • allow username-less login by probing discoverable credentials first, then fall back to the old flow
  • keep legacy (non-discoverable) registration/login paths working for older authenticators
  • Resolves: #

Summary

TODO

  • ...

Checklist

- require resident keys/UV for new FIDO2 registrations, but retry without if unsupported- allow username-less login by probing discoverable credentials first, then fall back to the old flow- keep legacy (non-discoverable) registration/login paths working for older authenticators
@susnux
Copy link
Contributor

Thank you for your contribution!
Pull requests need to go through the master branch first and then can be backported if needed.
So could you change the pull request target to master?

@swissbit-eis-admin
Copy link
Author

swissbit-eis-admin commentedDec 17, 2025 via email

OK, will do.ThxHubertusVon: Ferdinand Thiessen ***@***.***>Gesendet: Mittwoch, 17. Dezember 2025 13:44An: nextcloud/server ***@***.***>Cc: Hubertus Grobbel ***@***.***>; Author ***@***.***>Betreff: Re: [nextcloud/server] WebAuthn: prefer discoverable credentials with legacy fallback (PR#57140) CAUTION: This email is from an external source! / ACHTUNG: Diese E-Mail kommt von extern![https://avatars.githubusercontent.com/u/1855448?s=20&v=4]susnux left a comment (nextcloud/server#57140)<#57140 (comment)>Thank you for your contribution!Pull requests need to go through the master branch first and then can be backported if needed.So could you change the pull request target to master?-Reply to this email directly, view it on GitHub<#57140 (comment)>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/AZ4BICELBMTB462S6IXMFH34CFFYTAVCNFSM6AAAAACPJ2PYACVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZTMNRVGE4DCOJVGE>.You are receiving this because you authored the thread.Message ID: ***@***.******@***.***>>

@p1gp1g
Copy link
Contributor

Non-discoverable passkeys aren't "legacy", and they are useful when using a hardware tokens with limited number of key slots.

Registering a discoverable key should be an explicit action from the user:

  • there can be 2 buttons, one for the discoverable, another for the non-discoverable
  • or an input checkbox to use a discoverable or not

@swissbit-eis-admin
Copy link
Author

swissbit-eis-admin commentedDec 17, 2025 via email

OK, I will add a checkbox, no prob.The login method supports both methods anyhow.good idea!Von: S1m ***@***.***>Gesendet: Mittwoch, 17. Dezember 2025 14:04An: nextcloud/server ***@***.***>Cc: Hubertus Grobbel ***@***.***>; Author ***@***.***>Betreff: Re: [nextcloud/server] WebAuthn: prefer discoverable credentials with legacy fallback (PR#57140) CAUTION: This email is from an external source! / ACHTUNG: Diese E-Mail kommt von extern![https://avatars.githubusercontent.com/u/31284753?s=20&v=4]p1gp1g left a comment (nextcloud/server#57140)<#57140 (comment)>Non-discoverable passkeys aren't "legacy", and they are useful when using a hardware tokens with limited number of key slots.Registering a discoverable key should be an explicit action from the user: * there can be 2 buttons, one for the discoverable, another for the non-discoverable * or an input checkbox to use a discoverable or not-Reply to this email directly, view it on GitHub<#57140 (comment)>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/AZ4BICHL6PUG3ILX4ST33LD4CFIDVAVCNFSM6AAAAACPJ2PYACVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZTMNRVGI3DEOJSGQ>.You are receiving this because you authored the thread.Message ID: ***@***.******@***.***>>

@p1gp1g
Copy link
Contributor

With the setting, this is an appreciated feature 👍 (talking as a user).

BTW, we still need to fix this issue to get passkey only login:#44342

Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@nfebenfebeAwaiting requested review from nfebenfebe is a code owner automatically assigned from nextcloud/server-frontend

@skjnldsvskjnldsvAwaiting requested review from skjnldsvskjnldsv is a code owner automatically assigned from nextcloud/server-frontend

@sorbaughsorbaughAwaiting requested review from sorbaughsorbaugh is a code owner automatically assigned from nextcloud/server-frontend

@yemkareemsyemkareemsAwaiting requested review from yemkareemsyemkareems is a code owner automatically assigned from nextcloud/server-backend

@come-nccome-ncAwaiting requested review from come-nccome-nc is a code owner automatically assigned from nextcloud/server-backend

At least 2 approving reviews are required to merge this pull request.

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

3 participants

@swissbit-eis-admin@susnux@p1gp1g

[8]ページ先頭

©2009-2025 Movatter.jp