Class CredentialRecord

java.lang.Object
com.codename1.backend.security.webauthn.CredentialRecord

public final class CredentialRecord extends Object

One registered passkey: what the server keeps of a credential, as the WebAuthn specification's credential record lists it.

Nothing in it is secret. The public key verifies signatures and makes none, so a copy of this table signs nobody in.

  • Method Details

    • builder

      public static CredentialRecord.Builder builder()
    • from

      public static CredentialRecord.Builder from(CredentialRecord record)
      A builder that starts as a copy of record.
    • getCredentialId

      public byte[] getCredentialId()
      The credential's id, which the authenticator chose.
    • getUserEntityUserId

      public byte[] getUserEntityUserId()
      The handle of the user the credential belongs to; see PublicKeyCredentialUserEntity.getId().
    • getAlgorithm

      public long getAlgorithm()
      The COSE identifier of the key's algorithm; see CoseKey.
    • getPublicKey

      public byte[] getPublicKey()
      The public key, as a SubjectPublicKeyInfo in DER.
    • getSignatureCount

      public long getSignatureCount()
      The signature counter of the last ceremony. Zero for an authenticator that keeps none, as passkeys synced between devices do not.
    • isUvInitialized

      public boolean isUvInitialized()
      Whether the authenticator has ever verified the user with this credential: a PIN, a fingerprint, a face.
    • isBackupEligible

      public boolean isBackupEligible()
      Whether the credential may be backed up -- synced to the user's other devices. Settled when it is made and never changed.
    • isBackupState

      public boolean isBackupState()
      Whether it was backed up at its last ceremony.
    • getTransports

      public List<String> getTransports()
      How the authenticator said it can be reached: internal, hybrid, usb, nfc, ble. Sent back as a hint at sign-in.
    • getLabel

      public String getLabel()
      What the user called it; empty when they named it nothing.
    • getCreated

      public long getCreated()
      When it was registered, in epoch milliseconds.
    • getLastUsed

      public long getLastUsed()
      When it last signed in, in epoch milliseconds; when it was registered, until it has.