Class WebAuthnException


public final class WebAuthnException extends AuthenticationException

A passkey ceremony that was refused, with which check refused it.

getReason() is one of the constants here: a short name a test, a log line or an alert can match. The message says the same for a person, and may name what was received -- an origin, an attestation format -- so it is for the server's own log and is not sent to whoever made the request.

  • Field Details

    • MALFORMED

      public static final String MALFORMED
      The request is not the JSON a ceremony takes, or a field of it is missing or is not what it should be.
      See Also:
    • MALFORMED_CBOR

      public static final String MALFORMED_CBOR
      A CBOR value could not be read: truncated, nested too deep, too large, or of a kind the ceremonies have no use for.
      See Also:
    • NO_CHALLENGE

      public static final String NO_CHALLENGE
      No ceremony was waiting in this session, or it had been used already.
      See Also:
    • CHALLENGE_EXPIRED

      public static final String CHALLENGE_EXPIRED
      The ceremony was started too long ago.
      See Also:
    • CHALLENGE_MISMATCH

      public static final String CHALLENGE_MISMATCH
      The client signed another challenge than the one this session was given.
      See Also:
    • WRONG_TYPE

      public static final String WRONG_TYPE
      The client data is for the other ceremony: a registration where a sign-in was expected, or the reverse.
      See Also:
    • ORIGIN_MISMATCH

      public static final String ORIGIN_MISMATCH
      The ceremony ran on an origin the relying party does not allow.
      See Also:
    • CROSS_ORIGIN

      public static final String CROSS_ORIGIN
      The ceremony ran inside a frame of another origin, which is not allowed.
      See Also:
    • RP_ID_MISMATCH

      public static final String RP_ID_MISMATCH
      The authenticator answered for another relying party.
      See Also:
    • USER_NOT_PRESENT

      public static final String USER_NOT_PRESENT
      The authenticator did not see the user: the user-present flag is clear.
      See Also:
    • USER_NOT_VERIFIED

      public static final String USER_NOT_VERIFIED
      The ceremony required the user to be verified, and the flag is clear.
      See Also:
    • MALFORMED_AUTHENTICATOR_DATA

      public static final String MALFORMED_AUTHENTICATOR_DATA
      The authenticator data is not what the specification lays out.
      See Also:
    • UNSUPPORTED_ALGORITHM

      public static final String UNSUPPORTED_ALGORITHM
      The credential's key is of an algorithm this server does not verify.
      See Also:
    • INVALID_KEY

      public static final String INVALID_KEY
      The credential's key is not a key of the algorithm it names.
      See Also:
    • UNSUPPORTED_ATTESTATION

      public static final String UNSUPPORTED_ATTESTATION
      The attestation is in a format this server does not verify.
      See Also:
    • ATTESTATION_INVALID

      public static final String ATTESTATION_INVALID
      The attestation statement does not verify.
      See Also:
    • CREDENTIAL_EXISTS

      public static final String CREDENTIAL_EXISTS
      A credential with this id is registered already, to this user or another.
      See Also:
    • UNKNOWN_CREDENTIAL

      public static final String UNKNOWN_CREDENTIAL
      No credential with this id is registered.
      See Also:
    • CREDENTIAL_NOT_ALLOWED

      public static final String CREDENTIAL_NOT_ALLOWED
      The credential is not one the ceremony allowed.
      See Also:
    • USER_MISMATCH

      public static final String USER_MISMATCH
      The credential belongs to another user than the one the ceremony is for, or the response names no user where it must.
      See Also:
    • SIGNATURE_INVALID

      public static final String SIGNATURE_INVALID
      The signature is not the credential's signature of this ceremony.
      See Also:
    • COUNTER_REGRESSION

      public static final String COUNTER_REGRESSION
      The signature counter did not advance: the credential may have been copied.
      See Also:
    • BACKUP_STATE_INVALID

      public static final String BACKUP_STATE_INVALID
      The backup flags contradict each other, or what was recorded when the credential was registered.
      See Also:
    • ACCOUNT_UNAVAILABLE

      public static final String ACCOUNT_UNAVAILABLE
      The user the credential belongs to cannot sign in here.
      See Also:
  • Constructor Details

    • WebAuthnException

      public WebAuthnException(String reason, String message)
    • WebAuthnException

      public WebAuthnException(String reason, String message, Throwable cause)
  • Method Details

    • getReason

      public String getReason()
      Which check refused the ceremony: one of the constants of this class.