Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork4.7k
WebAuthn: prefer discoverable credentials with legacy fallback#57140
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
base:stable32
Are you sure you want to change the base?
WebAuthn: prefer discoverable credentials with legacy fallback#57140
Uh oh!
There was an error while loading.Please reload this page.
Conversation
- require resident keys/UV for new FIDO2 registrations, but retry without if unsupported- allow username-less login by probing discoverable credentials first, then fall back to the old flow- keep legacy (non-discoverable) registration/login paths working for older authenticators
susnux commentedDec 17, 2025
Thank you for your contribution! |
swissbit-eis-admin commentedDec 17, 2025 via email
OK, will do.ThxHubertusVon: Ferdinand Thiessen ***@***.***>Gesendet: Mittwoch, 17. Dezember 2025 13:44An: nextcloud/server ***@***.***>Cc: Hubertus Grobbel ***@***.***>; Author ***@***.***>Betreff: Re: [nextcloud/server] WebAuthn: prefer discoverable credentials with legacy fallback (PR#57140) CAUTION: This email is from an external source! / ACHTUNG: Diese E-Mail kommt von extern![https://avatars.githubusercontent.com/u/1855448?s=20&v=4]susnux left a comment (nextcloud/server#57140)<#57140 (comment)>Thank you for your contribution!Pull requests need to go through the master branch first and then can be backported if needed.So could you change the pull request target to master?-Reply to this email directly, view it on GitHub<#57140 (comment)>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/AZ4BICELBMTB462S6IXMFH34CFFYTAVCNFSM6AAAAACPJ2PYACVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZTMNRVGE4DCOJVGE>.You are receiving this because you authored the thread.Message ID: ***@***.******@***.***>> |
p1gp1g commentedDec 17, 2025
Non-discoverable passkeys aren't "legacy", and they are useful when using a hardware tokens with limited number of key slots. Registering a discoverable key should be an explicit action from the user:
|
swissbit-eis-admin commentedDec 17, 2025 via email
OK, I will add a checkbox, no prob.The login method supports both methods anyhow.good idea!Von: S1m ***@***.***>Gesendet: Mittwoch, 17. Dezember 2025 14:04An: nextcloud/server ***@***.***>Cc: Hubertus Grobbel ***@***.***>; Author ***@***.***>Betreff: Re: [nextcloud/server] WebAuthn: prefer discoverable credentials with legacy fallback (PR#57140) CAUTION: This email is from an external source! / ACHTUNG: Diese E-Mail kommt von extern![https://avatars.githubusercontent.com/u/31284753?s=20&v=4]p1gp1g left a comment (nextcloud/server#57140)<#57140 (comment)>Non-discoverable passkeys aren't "legacy", and they are useful when using a hardware tokens with limited number of key slots.Registering a discoverable key should be an explicit action from the user: * there can be 2 buttons, one for the discoverable, another for the non-discoverable * or an input checkbox to use a discoverable or not-Reply to this email directly, view it on GitHub<#57140 (comment)>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/AZ4BICHL6PUG3ILX4ST33LD4CFIDVAVCNFSM6AAAAACPJ2PYACVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZTMNRVGI3DEOJSGQ>.You are receiving this because you authored the thread.Message ID: ***@***.******@***.***>> |
p1gp1g commentedDec 17, 2025
With the setting, this is an appreciated feature 👍 (talking as a user). BTW, we still need to fix this issue to get passkey only login:#44342 |
Summary
TODO
Checklist
3. to review, feature component)stable32)