basalt / auth/src / WebAuthnService
Class: WebAuthnService
Defined in: auth/src/webauthn.ts:304
Constructors
Constructor
> new WebAuthnService(options): WebAuthnService
Defined in: auth/src/webauthn.ts:312
Parameters
options
Returns
WebAuthnService
Methods
finishAuthentication()
> finishAuthentication(sessionKey, response): Promise<{ credentialId: string; userId: string; }>
Defined in: auth/src/webauthn.ts:443
Verify an authentication response. Looks the credential up by its id, checks the signature counter increased (clone detection), persists the new counter with a compare-and-set (so two concurrent assertions cannot both pass), and returns whose passkey authenticated. Throws on any failure.
Parameters
sessionKey
string
response
unknown
Returns
Promise<{ credentialId: string; userId: string; }>
finishRegistration()
> finishRegistration(sessionKey, userId, response, deviceName?): Promise<PasskeyCredential>
Defined in: auth/src/webauthn.ts:374
Verify a registration response and store the new passkey. Throws on failure.
Parameters
sessionKey
string
userId
string
response
unknown
deviceName?
string
Returns
Promise<PasskeyCredential>
list()
> list(userId): Promise<PasskeyCredential[]>
Defined in: auth/src/webauthn.ts:495
A user's registered passkeys (for a "manage devices" screen).
Parameters
userId
string
Returns
Promise<PasskeyCredential[]>
remove()
> remove(userId, credentialId): Promise<void>
Defined in: auth/src/webauthn.ts:504
Remove one of userId's passkeys (revoke a device). The credential must belong to userId: a credential id is not an authorization, so an id that is unknown or owned by another user throws PasskeyNotFoundError (the same error for both, so the call cannot probe other users' devices).
Parameters
userId
string
credentialId
string
Returns
Promise<void>
startAuthentication()
> startAuthentication(sessionKey, userId?): Promise<AuthenticationOptions>
Defined in: auth/src/webauthn.ts:421
Authentication options; omit userId for discoverable login. With a userId (step-up, re-authentication) the challenge is bound to that user: finishAuthentication then refuses a passkey that belongs to anyone else, and allowCredentials lists only that user's passkeys.
Parameters
sessionKey
string
userId?
string
Returns
Promise<AuthenticationOptions>
startRegistration()
> startRegistration(sessionKey, user): Promise<RegistrationOptions>
Defined in: auth/src/webauthn.ts:351
Registration options for a known user; stores the challenge bound to user.id.
Parameters
sessionKey
string
user
displayName?
string
id
string
name
string
Returns
Promise<RegistrationOptions>