Skip to content

feat/arbitrary-data-signing#172

Merged
MasterKale merged 6 commits into
masterfrom
feat/arbitray-data-signing
Feb 2, 2022
Merged

feat/arbitrary-data-signing#172
MasterKale merged 6 commits into
masterfrom
feat/arbitray-data-signing

Conversation

@MasterKale

@MasterKale MasterKale commented Jan 29, 2022

Copy link
Copy Markdown
Owner

Issue #166 requested the ability to specify a method for challenge verification to allow for arbitrary data to be included in a registration challenge. I was at first disinclined to support such functionality since it was a use case not specifically defined in the spec, but two months later I figured what the heck, why not?

Now, after generating registration options, the challenge can be augmented with additional data:

const options = generateRegistrationOptions(opts);

// Remember the plain challenge
inMemoryUserDeviceDB[loggedInUserId].currentChallenge = options.challenge;

// Add data to be signed
options.challenge = base64url(JSON.stringify({
  actualChallenge: options.challenge,
  arbitraryData: 'arbitraryDataForSigning',
}));

Then, when invoking verifyRegistrationResponse(), pass in a method for expectedChallenge to parse the challenge and return a boolean:

const expectedChallenge = inMemoryUserDeviceDB[loggedInUserId].currentChallenge;

const verification = await verifyRegistrationResponse({
  expectedChallenge: (challenge: string) => {
    const parsedChallenge = JSON.parse(base64url.decode(challenge));
    return parsedChallenge.actualChallenge === expectedChallenge;
  },
  // ...
});

If you actually want the arbitrary data you'll need to use decodeClientDataJSON() afterwards to get it out:

import { decodeClientDataJSON } from '@simplewebauthn/server/helpers';

const { challenge } = decodeClientDataJSON(response.clientDataJSON);
const parsedChallenge = JSON.parse(base64url.decode(challenge));
console.log(parsedChallenge.arbitraryData); // 'arbitraryDataForSigning'

@MasterKale
MasterKale merged commit 9088870 into master Feb 2, 2022
@MasterKale
MasterKale deleted the feat/arbitray-data-signing branch February 2, 2022 06:11
@MasterKale MasterKale added the package:server @simplewebauthn/server label Feb 2, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

package:server @simplewebauthn/server

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant