summaryrefslogtreecommitdiff
path: root/api/auth/_verifyAuthenticationResponse.ts
diff options
context:
space:
mode:
authorJoe Carstairs <65492573+Sycamost@users.noreply.github.com>2023-12-21 21:22:47 +0000
committerJoe Carstairs <jcarstairs@scottlogic.com>2024-01-29 10:46:46 +0000
commit2d0634cdc3d00b3e55cf773ff03c7dc841112d36 (patch)
tree424f0b9ce2907e3d58336a2b25233bf0f9bead9d /api/auth/_verifyAuthenticationResponse.ts
parentf44b2a82b74337c6424c576fdbf4c1376166e553 (diff)
33 / Users can sign up and log in with WebAuthn (#39)
* Installs @vercel/postgres * Installs @simplewebauthn/server * Installs @simplewebauthn/browser * Git-ignores all files starting with .env * Reorganises folders in API * Defines User type * Defines Subscription type * Defines Authenticator type * Sets up table definition file * Can get user from database * Can add user to database * Can get user's current challenge * Can set user's current challenge * Can get user's authenticators from database * Can get authenticator by ID from database * Can add user authenticator to database * Can update authenticator in database * Defines Relying Party information * Can generate registration options * Can verify registration response * Defines registration API endpoint * Defines user API endpoint * Reorganises API functions on frontend * Can access authentication API functions on frontend * Can generate authentication options * Can verify authentication response * Documents the registration flow * Fix dev_csso * Form styling * WIP adds sign up page
Diffstat (limited to 'api/auth/_verifyAuthenticationResponse.ts')
-rw-r--r--api/auth/_verifyAuthenticationResponse.ts61
1 files changed, 61 insertions, 0 deletions
diff --git a/api/auth/_verifyAuthenticationResponse.ts b/api/auth/_verifyAuthenticationResponse.ts
new file mode 100644
index 0000000..7ef0e65
--- /dev/null
+++ b/api/auth/_verifyAuthenticationResponse.ts
@@ -0,0 +1,61 @@
+import type Authenticator from '../types/Authenticator';
+import type { AuthenticationResponseJSON, AuthenticatorDevice } from '@simplewebauthn/server/script/deps';
+
+import getCurrentChallenge from '../db/_getCurrentChallenge';
+import getUser from '../db/_getUser';
+import simplewebauthn from '@simplewebauthn/server';
+import RELYING_PARTY from './_relyingParty';
+import getAuthenticator from '../db/_getAuthenticator';
+import updateAuthenticator from '../db/_updateAuthenticator';
+
+/// Verifies the registration response returned by @simplewebauthn/browser's
+/// startAuthentication() method. Includes checking the provided challenge
+/// matches the most recent challenge for the salient user. If verification is
+/// successful, saves the new authenticator to the database.
+export default async function verifyAuthenticationResponse(
+ userId: string,
+ authenticatorId: string,
+ authenticationResponse: AuthenticationResponseJSON,
+): Promise<boolean> {
+ const user = await getUser(userId);
+ if (!user) {
+ return Promise.reject(`
+ Failed to verify authentication response because user with ID ${userId}
+ did not exist.
+ `);
+ }
+
+ const expectedChallenge = await getCurrentChallenge(userId);
+ if (!expectedChallenge) {
+ return Promise.reject(`
+ Failed to verify authentication response because user with ID ${userId}
+ did not have any existing challenges in the database.
+ `);
+ }
+
+ const textEncoder = new TextEncoder();
+ const fields: (keyof Authenticator)[] = ['id', 'publicKey', 'counter', 'transports'];
+ const authenticator = await getAuthenticator(authenticatorId, fields);
+ const adaptedAuthenticator: AuthenticatorDevice = {
+ credentialID: textEncoder.encode(authenticator.id),
+ credentialPublicKey: textEncoder.encode(authenticator.publicKey),
+ counter: authenticator.counter,
+ transports: authenticator.transports,
+ }
+
+ const verification = await simplewebauthn.verifyAuthenticationResponse({
+ response: authenticationResponse,
+ expectedChallenge,
+ expectedOrigin: origin,
+ expectedRPID: RELYING_PARTY.id,
+ authenticator: adaptedAuthenticator,
+ }).catch((err) => {
+ throw new Error('Registration response verification failed.', err);
+ });
+
+ if (!verification.verified) {
+ return false;
+ }
+
+ updateAuthenticator(authenticator.id, { counter: authenticator.counter + 1 });
+} \ No newline at end of file