Class WebAuthnRegistrationFilter

java.lang.Object
com.codename1.backend.security.WebAuthnRegistrationFilter
All Implemented Interfaces:
SecurityFilter

public final class WebAuthnRegistrationFilter extends Object implements SecurityFilter

Lets a signed-in user register a passkey, and remove one of theirs:

  • POST /webauthn/register/options answers the options to make one with;
  • POST /webauthn/register takes the authenticator's answer and stores the credential;
  • DELETE /webauthn/register/{credentialId} removes a credential, the id in base64url.

All three are for a user who signed in during this session. Somebody a remember-me cookie brought back is sent to sign in first: a stolen cookie must not be able to leave a passkey of the thief's behind. The filter runs after the chain's authorization rules, which say who may reach it at all.

The options are kept in the session, for five minutes unless set otherwise, and taken out of it before the answer is looked at.