From 2d0634cdc3d00b3e55cf773ff03c7dc841112d36 Mon Sep 17 00:00:00 2001 From: Joe Carstairs <65492573+Sycamost@users.noreply.github.com> Date: Thu, 21 Dec 2023 21:22:47 +0000 Subject: 33 / Users can sign up and log in with WebAuthn (#39) * Installs @vercel/postgres * Installs @simplewebauthn/server * Installs @simplewebauthn/browser * Git-ignores all files starting with .env * Reorganises folders in API * Defines User type * Defines Subscription type * Defines Authenticator type * Sets up table definition file * Can get user from database * Can add user to database * Can get user's current challenge * Can set user's current challenge * Can get user's authenticators from database * Can get authenticator by ID from database * Can add user authenticator to database * Can update authenticator in database * Defines Relying Party information * Can generate registration options * Can verify registration response * Defines registration API endpoint * Defines user API endpoint * Reorganises API functions on frontend * Can access authentication API functions on frontend * Can generate authentication options * Can verify authentication response * Documents the registration flow * Fix dev_csso * Form styling * WIP adds sign up page --- api/auth/_verifyAuthenticationResponse.ts | 61 +++++++++++++++++++++++++++++++ 1 file changed, 61 insertions(+) create mode 100644 api/auth/_verifyAuthenticationResponse.ts (limited to 'api/auth/_verifyAuthenticationResponse.ts') diff --git a/api/auth/_verifyAuthenticationResponse.ts b/api/auth/_verifyAuthenticationResponse.ts new file mode 100644 index 0000000..7ef0e65 --- /dev/null +++ b/api/auth/_verifyAuthenticationResponse.ts @@ -0,0 +1,61 @@ +import type Authenticator from '../types/Authenticator'; +import type { AuthenticationResponseJSON, AuthenticatorDevice } from '@simplewebauthn/server/script/deps'; + +import getCurrentChallenge from '../db/_getCurrentChallenge'; +import getUser from '../db/_getUser'; +import simplewebauthn from '@simplewebauthn/server'; +import RELYING_PARTY from './_relyingParty'; +import getAuthenticator from '../db/_getAuthenticator'; +import updateAuthenticator from '../db/_updateAuthenticator'; + +/// Verifies the registration response returned by @simplewebauthn/browser's +/// startAuthentication() method. Includes checking the provided challenge +/// matches the most recent challenge for the salient user. If verification is +/// successful, saves the new authenticator to the database. +export default async function verifyAuthenticationResponse( + userId: string, + authenticatorId: string, + authenticationResponse: AuthenticationResponseJSON, +): Promise { + const user = await getUser(userId); + if (!user) { + return Promise.reject(` + Failed to verify authentication response because user with ID ${userId} + did not exist. + `); + } + + const expectedChallenge = await getCurrentChallenge(userId); + if (!expectedChallenge) { + return Promise.reject(` + Failed to verify authentication response because user with ID ${userId} + did not have any existing challenges in the database. + `); + } + + const textEncoder = new TextEncoder(); + const fields: (keyof Authenticator)[] = ['id', 'publicKey', 'counter', 'transports']; + const authenticator = await getAuthenticator(authenticatorId, fields); + const adaptedAuthenticator: AuthenticatorDevice = { + credentialID: textEncoder.encode(authenticator.id), + credentialPublicKey: textEncoder.encode(authenticator.publicKey), + counter: authenticator.counter, + transports: authenticator.transports, + } + + const verification = await simplewebauthn.verifyAuthenticationResponse({ + response: authenticationResponse, + expectedChallenge, + expectedOrigin: origin, + expectedRPID: RELYING_PARTY.id, + authenticator: adaptedAuthenticator, + }).catch((err) => { + throw new Error('Registration response verification failed.', err); + }); + + if (!verification.verified) { + return false; + } + + updateAuthenticator(authenticator.id, { counter: authenticator.counter + 1 }); +} \ No newline at end of file -- cgit v1.2.3