Skip to content

[v15] Scoped WebAuthn: MFA extension flow#36973

Merged
Joerger merged 1 commit intobranch/v15from
joerger/v15/scoped-webauthn-extension-flow
Jan 22, 2024
Merged

[v15] Scoped WebAuthn: MFA extension flow#36973
Joerger merged 1 commit intobranch/v15from
joerger/v15/scoped-webauthn-extension-flow

Conversation

@Joerger
Copy link
Copy Markdown
Contributor

@Joerger Joerger commented Jan 20, 2024

Backport #36667 to branch/v15

Depends on #36958

@github-actions
Copy link
Copy Markdown
Contributor

The PR changelog entry failed validation: Changelog entry not found in the PR body. Please add a "no-changelog" label to the PR, or changelog lines starting with changelog: followed by the changelog entries for the PR.

@Joerger Joerger added the no-changelog Indicates that a PR does not require a changelog entry label Jan 20, 2024
Base automatically changed from joerger/v15/scoped-webauthn-session-data to branch/v15 January 20, 2024 03:07
* Use SessionData with extensions in Webauthn flow.

* Pass MFAChallengeExtensions through webauthn flow.

* Opportunistically enforce Webauthn challenge scope.

* Don't delete webauthn session data when reuse is allowed.

* Return more login data from webauthn flow.

* Enforce reuse when provided by the caller.

* Address comments.

* Fix test.

* Add unit test for scope and reuse.

* use pointer for challenge extension parameters.

* Address comments.
@Joerger Joerger force-pushed the joerger/v15/scoped-webauthn-extension-flow branch from 3c18586 to 8e28173 Compare January 21, 2024 21:21
@Joerger Joerger added this pull request to the merge queue Jan 22, 2024
Merged via the queue into branch/v15 with commit 581c480 Jan 22, 2024
@Joerger Joerger deleted the joerger/v15/scoped-webauthn-extension-flow branch January 22, 2024 18:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-changelog Indicates that a PR does not require a changelog entry size/md

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants