basalt / auth/src / PasskeyStore
Interface: PasskeyStore
Defined in: auth/src/webauthn.ts:29
Methods
add()
> add(credential): Promise<void>
Defined in: auth/src/webauthn.ts:30
Parameters
credential
Returns
Promise<void>
compareAndSetCounter()
> compareAndSetCounter(credentialId, expected, next, lastUsedAt): Promise<boolean>
Defined in: auth/src/webauthn.ts:41
Compare-and-set of the signature counter: stores next (and lastUsedAt) only if the stored counter still equals expected, and returns whether THIS call wrote it. Clone detection depends on it — with a read-then-write, a cloned authenticator used concurrently with the genuine one presents the same next counter twice and both assertions pass. Implement it as one conditional UPDATE (… WHERE id = ? AND counter = ?).
Parameters
credentialId
string
expected
number
next
number
lastUsedAt
number
Returns
Promise<boolean>
forUser()
> forUser(userId): Promise<PasskeyCredential[]>
Defined in: auth/src/webauthn.ts:32
Parameters
userId
string
Returns
Promise<PasskeyCredential[]>
get()
> get(credentialId): Promise<PasskeyCredential | null>
Defined in: auth/src/webauthn.ts:31
Parameters
credentialId
string
Returns
Promise<PasskeyCredential | null>
remove()
> remove(credentialId): Promise<void>
Defined in: auth/src/webauthn.ts:47
Parameters
credentialId
string
Returns
Promise<void>
updateCounter()?
> optional updateCounter(credentialId, counter, lastUsedAt): Promise<void>
Defined in: auth/src/webauthn.ts:46
Parameters
credentialId
string
counter
number
lastUsedAt
number
Returns
Promise<void>
Deprecated
Unconditional write, no longer called by WebAuthnService (it uses PasskeyStore.compareAndSetCounter).