Commit Graph
11 Commits
Author SHA1 Message Date
Hendrik BelitzandCopilot 78dfd9317a Mitigate account takeover in user registration process
Co-authored-by: Copilot <copilot@github.com>
2026-05-08 10:47:08 +02:00
Hendrik Belitz 3538d282ff Set preferred options so that yubikey works. 2026-02-16 10:43:40 +01:00
HendrikGitHubhbelcopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>Copilot
b81706a8d9 Security hotfix prf (#146)
* Use PRF extension for deterministic Zero Knowledge Shards

* Webauthn validation lib

* Use attestation and validate passkeys

* Use attestation objects and cose-format keys in frontend. Added additional checks so that we don't create orphaned users when validation fails.

* Fixed type check error

* Fix PRF salt documentation to match implementation (#147)

* Initial plan

* Fix PRF salt documentation to match implementation

Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>

* Use dev instead of node env

* Migration fixes

---------

Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>
2026-01-02 15:08:23 +01:00
CopilotGitHubhbelcopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>Hendrik Belitz
337fc2e70b Add throttling to challenge APIs for brute force protection (#145)
* Initial plan

* Add throttling implementation for challenge APIs

Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>

* Add tests for throttling and fix linting issues

Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>

* Address code review feedback - improve error handling and documentation

Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>

* Consolidate throttle storage to central DB per review feedback

Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>

* Fixed errors in challenge-throlle.

* Add throttling to frontend.

* incorporated Reviewer comments

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>
Co-authored-by: Hendrik Belitz <hendrik@innovation-through-understanding.de>
2026-01-02 13:14:40 +01:00
dc598a5146 Autosubmit login form on adding passkey (#78)
Co-authored-by: Karl Ludwig Weise <ludwig@ludwigweise.de>
2025-09-11 12:18:37 +02:00
1d4d8b888e Fix/auth fixes (#66)
* Fix session refresh

* Hardened passkey implementation

* Go to logout if session cannot be retrieved

---------

Co-authored-by: Karl Ludwig Weise <ludwig@ludwigweise.de>
2025-09-02 15:54:48 +02:00
bf610cac2b Change prettier settings (#65)
Co-authored-by: Karl Ludwig Weise <ludwig@ludwigweise.de>
2025-09-01 17:47:46 +02:00
Karl Ludwig Weise 93d6b00d94 Added login with passkey 2025-08-26 21:04:36 +02:00
Karl Ludwig Weise fd3b657443 Cleanup and debugging, but no fix for form sending 2025-08-26 14:51:14 +02:00
Hendrik Belitz 1b0ed692bd Fixed passkey structure on creation 2025-08-22 17:54:56 +02:00
Karl Ludwig Weise f76e9c9418 Cleanup 2025-08-22 16:05:45 +02:00