fix(auth): use direct attestation for registration/authentication #1764
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Moved from: supabase/auth-js#1126
Author: @Bewinxed
What kind of change does this PR introduce?
Fix/Enhancement
What is the current behavior?
The WebAuthn implementation currently sets
attestation: 'none'in the default creation options, which means the authenticator doesn't provide any attestation statement during registration.As per Yubico's Recommendation, this should be set to
directto allow us access to the make/model/version of the security keys being used. More InfoWhat is the new behavior?
Changed
attestationfrom'none'to'direct'inDEFAULT_CREATION_OPTIONS.Additional context
With
attestation: 'direct', the server can Verify authenticator make/model and possibly reject unknown models using the AAGUID of the security key.