Class WebAuthnRegistrationFilter
java.lang.Object
com.codename1.backend.security.WebAuthnRegistrationFilter
- All Implemented Interfaces:
SecurityFilter
Lets a signed-in user register a passkey, and remove one of theirs:
POST /webauthn/register/optionsanswers the options to make one with;POST /webauthn/registertakes the authenticator's answer and stores the credential;DELETE /webauthn/register/{credentialId}removes a credential, the id in base64url.
All three are for a user who signed in during this session. Somebody a remember-me cookie brought back is sent to sign in first: a stolen cookie must not be able to leave a passkey of the thief's behind. The filter runs after the chain's authorization rules, which say who may reach it at all.
The options are kept in the session, for five minutes unless set otherwise, and taken out of it before the answer is looked at.
-
Field Summary
Fields -
Method Summary
Modifier and TypeMethodDescriptiondoFilter(HttpServer.Request request, FilterChain chain) The answer torequest; null when nothing under the chain routes it, which the server answers 404.
-
Field Details
-
PENDING
The session attribute a registration's options wait under.- See Also:
-
-
Method Details
-
doFilter
Description copied from interface:SecurityFilterThe answer torequest; null when nothing under the chain routes it, which the server answers 404.- Specified by:
doFilterin interfaceSecurityFilter- Throws:
Exception
-