Class WebAuthnRelyingPartyOperations
The two passkey ceremonies, as the relying party performs them: making the options a client starts from, and verifying what the authenticator answered. Registration follows section 7.1 of the WebAuthn specification and sign-in section 7.2.
http.webAuthn(...) makes one and puts it behind the endpoints. An
application that serves the ceremonies itself uses it directly:
WebAuthnRelyingPartyOperations passkeys = new WebAuthnRelyingPartyOperations(
new PublicKeyCredentialRpEntity("example.com", "Example"),
Arrays.asList("https://example.com"), userEntities, credentials);
PublicKeyCredentialCreationOptions options =
passkeys.createPublicKeyCredentialCreationOptions("ada");
// ... keep options.toMap() for this user, send it, and with the answer:
CredentialRecord made = passkeys.registerCredential(options, answer, "Ada's phone");
What this class does not do is keep a ceremony's options between its two
requests, give a challenge a lifetime, or see that it is used once: the
caller holds the options and hands them back. The endpoints of
http.webAuthn(...) keep them in the session, for five minutes, and take
them out before they look at the answer.
What is verified
Both ceremonies: that the client data is of the right ceremony, carries this challenge, and names an origin among those allowed -- compared as text, in full -- and no frame of another origin; that the authenticator answered for this relying party; that the user was present, and verified when the options required it; that the backup flags are possible.
Registration: that the credential's key is ES256 or RS256; the
attestation, which must be none, or packed signed by the credential's
own key -- any other is refused by name unless
setAllowUnverifiedAttestation(boolean); and that no credential has this id.
Sign-in: that the credential is registered and, when the user said who they are first, is one of theirs; that the user the answer names owns it; the signature, over the authenticator data and the hash of the client data; that the signature counter moved forward; that the credential is as eligible for backup as when it was made.
A refusal is a WebAuthnException whose reason says which of these it was.
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic final classA verified sign-in.static interfaceTold when a signature counter did not advance. -
Constructor Summary
ConstructorsConstructorDescriptionWebAuthnRelyingPartyOperations(PublicKeyCredentialRpEntity rp, Collection<String> allowedOrigins, PublicKeyCredentialUserEntityRepository users, UserCredentialRepository credentials) -
Method Summary
Modifier and TypeMethodDescriptionauthenticate(PublicKeyCredentialRequestOptions options, Map credential) Verifies the answer tooptions, and records the sign-in on the credential.createCredentialRequestOptions(String username) The options to sign in with.The options forusernameto make a passkey with.getRp()The credentials this was made with.The user entities this was made with.registerCredential(PublicKeyCredentialCreationOptions options, Map credential, String label) Verifies the answer tooptionsand stores the credential.voidsetAllowCrossOrigin(boolean allowCrossOrigin) Whether a ceremony may run inside a frame of another origin than the page around it.voidsetAllowUnverifiedAttestation(boolean allowUnverifiedAttestation) Whether a registration whose attestation this server cannot verify --packedwith a certificate chain,tpm,apple,android-key,fido-u2fand the rest -- is accepted as if it carried none.voidsetAuthenticatorAttachment(String authenticatorAttachment) platformfor the device's own authenticator,cross-platformfor a security key, or null -- the default -- for either.voidThe clock records are dated from; for tests.voidsetResidentKey(String residentKey) Whether a new credential must be one a sign-in can find without being told the user:required, the default, which is what makes it a passkey;preferred; ordiscouraged.voidWhat is told of a signature counter that did not advance.voidsetTimeoutMillis(long timeoutMillis) The timeout the options carry, in milliseconds; five minutes unless set.voidsetUserVerification(String userVerification) Whether the authenticator must verify the user --required-- should when it can --preferred, the default -- or need not:discouraged.
-
Constructor Details
-
WebAuthnRelyingPartyOperations
public WebAuthnRelyingPartyOperations(PublicKeyCredentialRpEntity rp, Collection<String> allowedOrigins, PublicKeyCredentialUserEntityRepository users, UserCredentialRepository credentials) - Parameters:
allowedOrigins- the origins a ceremony may run on, each exactly as a client reports it:https://example.com, with a port when it is not the default and no path; and for an Android application,android:apk-key-hash:followed by the base64url SHA-256 of its signing certificate
-
-
Method Details
-
setUserVerification
Whether the authenticator must verify the user --required-- should when it can --preferred, the default -- or need not:discouraged. -
setResidentKey
Whether a new credential must be one a sign-in can find without being told the user:required, the default, which is what makes it a passkey;preferred; ordiscouraged. -
setAuthenticatorAttachment
platformfor the device's own authenticator,cross-platformfor a security key, or null -- the default -- for either. -
setTimeoutMillis
public void setTimeoutMillis(long timeoutMillis) The timeout the options carry, in milliseconds; five minutes unless set. -
setAllowUnverifiedAttestation
public void setAllowUnverifiedAttestation(boolean allowUnverifiedAttestation) Whether a registration whose attestation this server cannot verify --
packedwith a certificate chain,tpm,apple,android-key,fido-u2fand the rest -- is accepted as if it carried none. Off unless set: such a registration is refused with a message that names the format.Accepting one loses nothing a server that asks for no attestation relies on: the statement vouches for the authenticator's make, and the credential is verified at every sign-in either way. It is off so that a format nobody looked at is noticed rather than waved through.
-
setAllowCrossOrigin
public void setAllowCrossOrigin(boolean allowCrossOrigin) Whether a ceremony may run inside a frame of another origin than the page around it. Off unless set. -
setClock
The clock records are dated from; for tests. -
setSignatureCounterListener
public void setSignatureCounterListener(WebAuthnRelyingPartyOperations.SignatureCounterListener listener) What is told of a signature counter that did not advance. -
getRp
-
getUserEntities
The user entities this was made with. -
getUserCredentials
The credentials this was made with. -
createPublicKeyCredentialCreationOptions
The options forusernameto make a passkey with. Gives the user a handle if they have none, and lists the credentials they have so that an authenticator holding one of them makes no second. -
registerCredential
public CredentialRecord registerCredential(PublicKeyCredentialCreationOptions options, Map credential, String label) Verifies the answer tooptionsand stores the credential.- Parameters:
options- what the client was given, as kept sincecredential- the client's answer, parsed: the WebAuthnRegistrationResponseJSONlabel- what the user calls the passkey; may be null- Returns:
- the credential as stored
- Throws:
WebAuthnException- when the answer is refused
-
createCredentialRequestOptions
The options to sign in with.- Parameters:
username- the user, when they said who they are first: the options then list their credentials, and only one of those is accepted. Null for a sign-in that names nobody, which any passkey of this relying party may answer. A name with no passkey gets the same options as null.
-
authenticate
public WebAuthnRelyingPartyOperations.Assertion authenticate(PublicKeyCredentialRequestOptions options, Map credential) Verifies the answer tooptions, and records the sign-in on the credential.- Parameters:
options- what the client was given, as kept sincecredential- the client's answer, parsed: the WebAuthnAuthenticationResponseJSON- Throws:
WebAuthnException- when the answer is refused
-