Skip to content

fix: require discoverable credentials for passkey registration - #92

Merged
vitorhugo-dotnet merged 1 commit into
mainfrom
fix/passkey-discoverable-registration
Sep 17, 2026
Merged

vitorhugo-dotnet merged 1 commit into
mainfrom
fix/passkey-discoverable-registration

Conversation

@vitorhugo-dotnet

@vitorhugo-dotnet vitorhugo-dotnet commented Sep 17, 2026 •

Copy link
Copy Markdown
Owner

Root cause

The backend already starts username-less assertions, but passkey registration omitted authenticatorSelection.residentKey. This allowed creation of non-discoverable credentials, which cannot be selected for username-less login.

Fix

Configure registration with:

AuthenticatorSelectionCriteria.builder().residentKey(ResidentKeyRequirement.REQUIRED).build()

and pass it to StartRegistrationOptions.

REQUIRED is intentional: username-less authentication depends on a discoverable credential; PREFERRED would not guarantee one.

No frontend changes were required.

Regression test

Added PasskeyRegistrationOptionsIT, validating the actual HTTP registration-options response contains:

publicKey.authenticatorSelection.residentKey = "required".

TDD proof:

  • Before fix: mvn -B -ntp -Dtest=PasskeyRegistrationOptionsIT test failed because authenticatorSelection.residentKey was missing.
  • After fix: the same command passes.

Verification

  • mvn -B -ntp -Dtest=PasskeyRegistrationOptionsIT test — PASS
  • mvn -B -ntp clean verify — PASS

Compatibility

Passkeys registered before this fix may be non-discoverable. Those credentials may need to be removed and registered again after deployment.

@github-actions

Copy link
Copy Markdown

Qodana for JVM

3 new problems were found

Inspection name Severity Problems
Nullability and data flow problems 🔶 Warning 1
Mismatched query and update of 'StringBuilder' 🔶 Warning 1
Simplifiable conditional expression 🔶 Warning 1
View the detailed Qodana report

To be able to view the detailed Qodana report, you can either:

To get *.log files or any other Qodana artifacts, run the action with upload-result option set to true,
so that the action will upload the files as the job artifacts:

      - name: 'Qodana Scan'
        uses: JetBrains/qodana-action@v2025.3.2
        with:
          upload-result: true
Contact Qodana team

Contact us at qodana-support@jetbrains.com

@vitorhugo-dotnet
vitorhugo-dotnet force-pushed the fix/passkey-discoverable-registration branch from 5f47ba8 to 1fefbea Compare September 17, 2026 13:47
@vitorhugo-dotnet
vitorhugo-dotnet marked this pull request as ready for review September 17, 2026 13:53
@vitorhugo-dotnet
vitorhugo-dotnet merged commit b1bb4f4 into main Sep 17, 2026
6 checks passed
@vitorhugo-dotnet
vitorhugo-dotnet deleted the fix/passkey-discoverable-registration branch September 17, 2026 13:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant