Passkeys, so signing in needs no password at all #47
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
Depends on
Reference
Postulo/postulo#47
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Observation
What exists today
MFA_SUPPORTED_TYPES = ["totp", "recovery_codes"]inconfig/settings/base.py, withMFA_TRUST_ENABLEDfor a thirty-day trusted device.django-allauth[mfa]65.19, and that extra already bringsfido2.The installed version supports WebAuthn, so this is configuration, templates, words
and tests rather than new protocol code.
Shape
"webauthn"toMFA_SUPPORTED_TYPES, and turn onMFA_PASSKEY_LOGIN_ENABLEDso apasskey is a way in rather than only a second factor.
MFA_PASSKEY_SIGNUP_ENABLEDstays off: an instance decides who may register (#3), and a passkey at sign-up does not
change that decision.
remove one. Removing the last passkey from an account with no password is refused, for
the same reason the last administrator cannot be deleted.
WEBAUTHN_RP_ID, the instance's hostname. An instance reachedat two names, or moved to a new one, invalidates every passkey on it. The settings page
and Configuration both have to say so plainly rather than leaving somebody locked out
of their own record.
localhostexcepted. The page says so ratherthan failing silently on an instance served over plain HTTP.
first passkey should offer them, not mention them.
Classification
Enhancement. Not breaking: passwords keep working, and an instance that turns nothing on
behaves exactly as it does today.
Depends on
Nothing. #48 depends on this.
Open questions
recovery codes exist.