From 2d0634cdc3d00b3e55cf773ff03c7dc841112d36 Mon Sep 17 00:00:00 2001 From: Joe Carstairs <65492573+Sycamost@users.noreply.github.com> Date: Thu, 21 Dec 2023 21:22:47 +0000 Subject: 33 / Users can sign up and log in with WebAuthn (#39) * Installs @vercel/postgres * Installs @simplewebauthn/server * Installs @simplewebauthn/browser * Git-ignores all files starting with .env * Reorganises folders in API * Defines User type * Defines Subscription type * Defines Authenticator type * Sets up table definition file * Can get user from database * Can add user to database * Can get user's current challenge * Can set user's current challenge * Can get user's authenticators from database * Can get authenticator by ID from database * Can add user authenticator to database * Can update authenticator in database * Defines Relying Party information * Can generate registration options * Can verify registration response * Defines registration API endpoint * Defines user API endpoint * Reorganises API functions on frontend * Can access authentication API functions on frontend * Can generate authentication options * Can verify authentication response * Documents the registration flow * Fix dev_csso * Form styling * WIP adds sign up page --- api/auth/_generateAuthenticationOptions.ts | 47 ++++++++++++++++++++++++++++++ 1 file changed, 47 insertions(+) create mode 100644 api/auth/_generateAuthenticationOptions.ts (limited to 'api/auth/_generateAuthenticationOptions.ts') diff --git a/api/auth/_generateAuthenticationOptions.ts b/api/auth/_generateAuthenticationOptions.ts new file mode 100644 index 0000000..562c50a --- /dev/null +++ b/api/auth/_generateAuthenticationOptions.ts @@ -0,0 +1,47 @@ +import RELYING_PARTY from './_relyingParty'; +import simplewebauthn from '@simplewebauthn/server'; +import getUser from '../db/_getUser'; +import getAuthenticators from '../db/_getAuthenticators'; +import setCurrentChallenge from '../db/_setCurrentChallenge'; + +/** + * Generates options for a user with an existing account on the website to + * authenticate using an authenticator which is already associated with their + * account in the database. + * + * If a user doesn't currently have an account, they have to create one first, + * get their account ID and register an authenticator. + * + * The result should be consumed by \@simplewebauthn/browser's + * `startAuthentication()` method. + */ +export default async function generateAuthenticationOptions(userId: string) { + const user = await getUser(userId); + if (!user) { + return Promise.reject(` + Failed to generate authentication options because user with ID ${userId} + did not exist. + `); + } + + const userAuthenticators = await getAuthenticators(userId, ['id', 'transports', 'type']); + const textEncoder = new TextEncoder(); + + const options = await simplewebauthn.generateAuthenticationOptions({ + rpID: RELYING_PARTY.id, + + // Users must use one of the authenticators they've already registered + allowCredentials: userAuthenticators.map((authenticator) => { + return { + ...authenticator, + id: textEncoder.encode(authenticator.id), + }; + }), + + userVerification: 'preferred', + }); + + setCurrentChallenge(userId, options.challenge); + + return options; +} -- cgit v1.2.3