Class CredentialRecord
java.lang.Object
com.codename1.backend.security.webauthn.CredentialRecord
One registered passkey: what the server keeps of a credential, as the WebAuthn specification's credential record lists it.
Nothing in it is secret. The public key verifies signatures and makes none, so a copy of this table signs nobody in.
-
Nested Class Summary
Nested Classes -
Method Summary
Modifier and TypeMethodDescriptionstatic CredentialRecord.Builderbuilder()static CredentialRecord.Builderfrom(CredentialRecord record) A builder that starts as a copy ofrecord.longThe COSE identifier of the key's algorithm; seeCoseKey.longWhen it was registered, in epoch milliseconds.byte[]The credential's id, which the authenticator chose.getLabel()What the user called it; empty when they named it nothing.longWhen it last signed in, in epoch milliseconds; when it was registered, until it has.byte[]The public key, as a SubjectPublicKeyInfo in DER.longThe signature counter of the last ceremony.How the authenticator said it can be reached:internal,hybrid,usb,nfc,ble.byte[]The handle of the user the credential belongs to; seePublicKeyCredentialUserEntity.getId().booleanWhether the credential may be backed up -- synced to the user's other devices.booleanWhether it was backed up at its last ceremony.booleanWhether the authenticator has ever verified the user with this credential: a PIN, a fingerprint, a face.
-
Method Details
-
builder
-
from
A builder that starts as a copy ofrecord. -
getCredentialId
public byte[] getCredentialId()The credential's id, which the authenticator chose. -
getUserEntityUserId
public byte[] getUserEntityUserId()The handle of the user the credential belongs to; seePublicKeyCredentialUserEntity.getId(). -
getAlgorithm
public long getAlgorithm()The COSE identifier of the key's algorithm; seeCoseKey. -
getPublicKey
public byte[] getPublicKey()The public key, as a SubjectPublicKeyInfo in DER. -
getSignatureCount
public long getSignatureCount()The signature counter of the last ceremony. Zero for an authenticator that keeps none, as passkeys synced between devices do not. -
isUvInitialized
public boolean isUvInitialized()Whether the authenticator has ever verified the user with this credential: a PIN, a fingerprint, a face. -
isBackupEligible
public boolean isBackupEligible()Whether the credential may be backed up -- synced to the user's other devices. Settled when it is made and never changed. -
isBackupState
public boolean isBackupState()Whether it was backed up at its last ceremony. -
getTransports
-
getLabel
What the user called it; empty when they named it nothing. -
getCreated
public long getCreated()When it was registered, in epoch milliseconds. -
getLastUsed
public long getLastUsed()When it last signed in, in epoch milliseconds; when it was registered, until it has.
-