You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Allow configuring WebAuthn userVerification (currently hardcoded to "discouraged")
#7621
Currently, userVerification in the WebAuthn challenge response is hardcoded to "discouraged". This means biometric FIDO2 keys (e.g. fingerprint sensors) never actually verify the biometric — the sensor just acts as a touch button, and any finger works.
It would be great to have an option (env var or admin panel setting) to set userVerification to "preferred" or "required", so biometric security keys can actually enforce fingerprint matching as part of the WebAuthn 2FA flow.
Use case: using a FIDO2 security key with a fingerprint sensor as a 2FA method, expecting the fingerprint to be verified — but currently any touch on the sensor is accepted regardless of whose finger it is.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Currently,
userVerificationin the WebAuthn challenge response is hardcoded to"discouraged". This means biometric FIDO2 keys (e.g. fingerprint sensors) never actually verify the biometric — the sensor just acts as a touch button, and any finger works.It would be great to have an option (env var or admin panel setting) to set
userVerificationto"preferred"or"required", so biometric security keys can actually enforce fingerprint matching as part of the WebAuthn 2FA flow.Use case: using a FIDO2 security key with a fingerprint sensor as a 2FA method, expecting the fingerprint to be verified — but currently any touch on the sensor is accepted regardless of whose finger it is.
All reactions