summaryrefslogtreecommitdiff
path: root/api/auth/_verifyAuthenticationResponse.ts
blob: c81906073ed677851b244fb189197f2383cdfd62 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
import type Authenticator from '../types/Authenticator';
import type { AuthenticationResponseJSON, AuthenticatorDevice } from '@simplewebauthn/server/script/deps';

import simplewebauthn from '@simplewebauthn/server';
import RELYING_PARTY from './_relyingParty';

/// Verifies the registration response returned by @simplewebauthn/browser's
/// startAuthentication() method.
export default async function verifyAuthenticationResponse(
  authenticator: Pick<Authenticator, 'id' | 'publicKey' | 'counter' | 'transports'>,
  authenticationResponse: AuthenticationResponseJSON,
  expectedChallenge: string,
): Promise<boolean> {
  const adaptedAuthenticator: AuthenticatorDevice = {
    credentialID: authenticator.id,
    credentialPublicKey: authenticator.publicKey,
    counter: authenticator.counter,
    transports: authenticator.transports,
  }

  const verification = await simplewebauthn.verifyAuthenticationResponse({
    response: authenticationResponse,
    expectedChallenge,
    expectedOrigin: origin,
    expectedRPID: RELYING_PARTY.id,
    authenticator: adaptedAuthenticator,
  }).catch((err) => {
    throw new Error('Registration response verification failed.', err);
  });

  if (!verification.verified) {
    return false;
  }
}