From 2d0634cdc3d00b3e55cf773ff03c7dc841112d36 Mon Sep 17 00:00:00 2001 From: Joe Carstairs <65492573+Sycamost@users.noreply.github.com> Date: Thu, 21 Dec 2023 21:22:47 +0000 Subject: 33 / Users can sign up and log in with WebAuthn (#39) * Installs @vercel/postgres * Installs @simplewebauthn/server * Installs @simplewebauthn/browser * Git-ignores all files starting with .env * Reorganises folders in API * Defines User type * Defines Subscription type * Defines Authenticator type * Sets up table definition file * Can get user from database * Can add user to database * Can get user's current challenge * Can set user's current challenge * Can get user's authenticators from database * Can get authenticator by ID from database * Can add user authenticator to database * Can update authenticator in database * Defines Relying Party information * Can generate registration options * Can verify registration response * Defines registration API endpoint * Defines user API endpoint * Reorganises API functions on frontend * Can access authentication API functions on frontend * Can generate authentication options * Can verify authentication response * Documents the registration flow * Fix dev_csso * Form styling * WIP adds sign up page --- api/auth/_generateRegistrationOptionsForNewUser.ts | 33 ++++++++++++++++++++++ 1 file changed, 33 insertions(+) create mode 100644 api/auth/_generateRegistrationOptionsForNewUser.ts (limited to 'api/auth/_generateRegistrationOptionsForNewUser.ts') diff --git a/api/auth/_generateRegistrationOptionsForNewUser.ts b/api/auth/_generateRegistrationOptionsForNewUser.ts new file mode 100644 index 0000000..b9417e9 --- /dev/null +++ b/api/auth/_generateRegistrationOptionsForNewUser.ts @@ -0,0 +1,33 @@ +import RELYING_PARTY from './_relyingParty'; +import { generateRegistrationOptions } from '@simplewebauthn/server'; + +/** + * Generates options for a user without an existing account on the website to + * register a new authenticator and remembers the generated challenge. + * + * This function assumes that no user already exists with the given ID. + * It's the responsibility of the caller to make sure this assumption is true. + * + * If the user already has an account, they can't yet add more authenticators. + * This feature might be added in a future version of the website if there is a + * demonstrable need for it (or if I just get bored one day). + */ +export default async function generateRegistrationOptionsForNewUser(userId: string, displayName: string) { + const options = await generateRegistrationOptions({ + rpName: RELYING_PARTY.name, + rpID: RELYING_PARTY.id, + + userID: userId, + userName: displayName, + + // Don't prompt users for additional information about the authenticator + attestationType: 'none', + + // Prevents users from re-registering existing authenticators. In our case, + // we only allow new users right now, so they don't have any existing + // authenticators. + excludeCredentials: [] + }); + + return options; +} -- cgit v1.2.3