Skip to content

5.3.6

@Spomky Spomky tagged this 20 Aug 12:26
* fix(authenticator-data): restrict FLAG_RFU2 to bit 5

Bits 3 and 4 were reserved in Webauthn Level 2 and have been assigned to
BE (Backup Eligibility) and BS (Backup State) in Level 3. The mask was
never narrowed, so getReservedForFutureUse2() reported the backup flags
a second time: a synced passkey with BE and BS set returned 24 instead
of 0.

Closes #920

* fix(prf): base64url encode the evalByCredential keys

The specification requires the keys of the evalByCredential map to be
the base64url encoding of the credential ID, and the client rejects the
ceremony with a SyntaxError otherwise. The builder encoded the salts but
used the credential ID as given, which made a raw credential ID produce
an invalid key.

Closes #924

* fix(client-data): stop validating the reserved tokenBinding member

tokenBinding is [RESERVED] since Webauthn Level 3. The value was never
read nor exposed, so the only effect of the check was to fail a ceremony
over a member the Relying Party does not use, with a truncated error
message. The raw client data remains available through the data
property.

Closes #929

* test(cose): cover variable-length DER INTEGER signatures

The ASN.1 DER encoding of an ECDSA signature has a variable length, as
w3c/webauthn#2315 now makes explicit in the specification example. The
class handling the conversion had no test at all.

Closes #930
Assets 2
Loading