summaryrefslogtreecommitdiff
path: root/api/auth/_generateRegistrationOptionsForNewUser.ts
diff options
context:
space:
mode:
authorJoe Carstairs <65492573+Sycamost@users.noreply.github.com>2023-12-21 21:22:47 +0000
committerJoe Carstairs <jcarstairs@scottlogic.com>2024-01-29 10:46:46 +0000
commit2d0634cdc3d00b3e55cf773ff03c7dc841112d36 (patch)
tree424f0b9ce2907e3d58336a2b25233bf0f9bead9d /api/auth/_generateRegistrationOptionsForNewUser.ts
parentf44b2a82b74337c6424c576fdbf4c1376166e553 (diff)
33 / Users can sign up and log in with WebAuthn (#39)
* Installs @vercel/postgres * Installs @simplewebauthn/server * Installs @simplewebauthn/browser * Git-ignores all files starting with .env * Reorganises folders in API * Defines User type * Defines Subscription type * Defines Authenticator type * Sets up table definition file * Can get user from database * Can add user to database * Can get user's current challenge * Can set user's current challenge * Can get user's authenticators from database * Can get authenticator by ID from database * Can add user authenticator to database * Can update authenticator in database * Defines Relying Party information * Can generate registration options * Can verify registration response * Defines registration API endpoint * Defines user API endpoint * Reorganises API functions on frontend * Can access authentication API functions on frontend * Can generate authentication options * Can verify authentication response * Documents the registration flow * Fix dev_csso * Form styling * WIP adds sign up page
Diffstat (limited to 'api/auth/_generateRegistrationOptionsForNewUser.ts')
-rw-r--r--api/auth/_generateRegistrationOptionsForNewUser.ts33
1 files changed, 33 insertions, 0 deletions
diff --git a/api/auth/_generateRegistrationOptionsForNewUser.ts b/api/auth/_generateRegistrationOptionsForNewUser.ts
new file mode 100644
index 0000000..b9417e9
--- /dev/null
+++ b/api/auth/_generateRegistrationOptionsForNewUser.ts
@@ -0,0 +1,33 @@
+import RELYING_PARTY from './_relyingParty';
+import { generateRegistrationOptions } from '@simplewebauthn/server';
+
+/**
+ * Generates options for a user without an existing account on the website to
+ * register a new authenticator and remembers the generated challenge.
+ *
+ * This function assumes that no user already exists with the given ID.
+ * It's the responsibility of the caller to make sure this assumption is true.
+ *
+ * If the user already has an account, they can't yet add more authenticators.
+ * This feature might be added in a future version of the website if there is a
+ * demonstrable need for it (or if I just get bored one day).
+ */
+export default async function generateRegistrationOptionsForNewUser(userId: string, displayName: string) {
+ const options = await generateRegistrationOptions({
+ rpName: RELYING_PARTY.name,
+ rpID: RELYING_PARTY.id,
+
+ userID: userId,
+ userName: displayName,
+
+ // Don't prompt users for additional information about the authenticator
+ attestationType: 'none',
+
+ // Prevents users from re-registering existing authenticators. In our case,
+ // we only allow new users right now, so they don't have any existing
+ // authenticators.
+ excludeCredentials: []
+ });
+
+ return options;
+}