passwordless login + proper migrations
This commit is contained in:
+125
-56
@@ -7,12 +7,13 @@ use webauthn_rs::{
|
||||
error::WebauthnError as WanError,
|
||||
proto::{
|
||||
CreationChallengeResponse, Credential, PublicKeyCredential, RegisterPublicKeyCredential,
|
||||
RequestChallengeResponse,
|
||||
RequestChallengeResponse, UserVerificationPolicy,
|
||||
},
|
||||
};
|
||||
|
||||
use crate::domain::{DomainError, DomainResult, Passkey as DbPasskey, User};
|
||||
use crate::ports::PasskeyRepository;
|
||||
use crate::ports::{PasskeyRepository, UserRepository};
|
||||
use crate::security::new_secret;
|
||||
use crate::sqlite::SqliteDatabase;
|
||||
|
||||
/// Site-specific WebAuthn configuration, derived from env vars.
|
||||
@@ -20,6 +21,7 @@ pub struct AppWebauthnConfig {
|
||||
rp_id: String,
|
||||
rp_name: String,
|
||||
origin: url::Url,
|
||||
require_resident_key: bool,
|
||||
}
|
||||
|
||||
impl AppWebauthnConfig {
|
||||
@@ -28,6 +30,10 @@ impl AppWebauthnConfig {
|
||||
rp_id,
|
||||
rp_name,
|
||||
origin,
|
||||
// Resident (discoverable) keys let users sign in without typing an
|
||||
// email, because the authenticator can select the credential on its
|
||||
// own and return the user handle.
|
||||
require_resident_key: true,
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -42,18 +48,24 @@ impl WebauthnConfig for AppWebauthnConfig {
|
||||
fn get_relying_party_id(&self) -> &str {
|
||||
&self.rp_id
|
||||
}
|
||||
fn get_require_resident_key(&self) -> bool {
|
||||
self.require_resident_key
|
||||
}
|
||||
}
|
||||
|
||||
/// A single-use, in-memory challenge store keyed by user id.
|
||||
/// A single-use, in-memory challenge store. Registrations are keyed by user id;
|
||||
/// authentications are keyed by a random token so that userless (discoverable)
|
||||
/// ceremonies can be correlated back to the finish request.
|
||||
#[derive(Default)]
|
||||
struct ChallengeStore {
|
||||
registrations: HashMap<i64, RegistrationState>,
|
||||
authentications: HashMap<i64, AuthenticationState>,
|
||||
authentications: HashMap<String, AuthenticationState>,
|
||||
}
|
||||
|
||||
pub struct WebAuthnService {
|
||||
db: SqliteDatabase,
|
||||
webauthn: Webauthn<AppWebauthnConfig>,
|
||||
users: Arc<dyn UserRepository>,
|
||||
passkeys: Arc<dyn PasskeyRepository>,
|
||||
challenges: Mutex<ChallengeStore>,
|
||||
}
|
||||
@@ -62,12 +74,14 @@ impl WebAuthnService {
|
||||
pub fn new(
|
||||
db: SqliteDatabase,
|
||||
config: AppWebauthnConfig,
|
||||
users: Arc<dyn UserRepository>,
|
||||
passkeys: Arc<dyn PasskeyRepository>,
|
||||
) -> Self {
|
||||
let webauthn = Webauthn::new(config);
|
||||
Self {
|
||||
db,
|
||||
webauthn,
|
||||
users,
|
||||
passkeys,
|
||||
challenges: Mutex::new(ChallengeStore::default()),
|
||||
}
|
||||
@@ -75,9 +89,19 @@ impl WebAuthnService {
|
||||
|
||||
/// Start a passkey registration ceremony for an authenticated user.
|
||||
pub fn start_registration(&self, user: &User) -> DomainResult<CreationChallengeResponse> {
|
||||
// Use the user's opaque, random user handle as the WebAuthn userHandle
|
||||
// so that userless (discoverable) sign-in can resolve the owning user
|
||||
// from the assertion's userHandle without exposing the numeric id.
|
||||
let (challenge, state) = self
|
||||
.webauthn
|
||||
.generate_challenge_register(&user.display_name, true)
|
||||
.generate_challenge_register_options(
|
||||
user.user_handle.clone(),
|
||||
user.email.clone(),
|
||||
user.display_name.clone(),
|
||||
None,
|
||||
Some(UserVerificationPolicy::Required),
|
||||
None,
|
||||
)
|
||||
.map_err(webauthn_error)?;
|
||||
self.challenges
|
||||
.lock()
|
||||
@@ -127,11 +151,12 @@ impl WebAuthnService {
|
||||
.await
|
||||
}
|
||||
|
||||
/// Start a passkey authentication ceremony for a user.
|
||||
/// Start a passkey authentication ceremony for a user identified by email.
|
||||
/// Returns the challenge and a token used to correlate the finish request.
|
||||
pub async fn start_authentication(
|
||||
&self,
|
||||
user_id: i64,
|
||||
) -> DomainResult<RequestChallengeResponse> {
|
||||
) -> DomainResult<(RequestChallengeResponse, String)> {
|
||||
let passkeys = Arc::clone(&self.passkeys);
|
||||
let db = self.db.clone();
|
||||
let credentials: Vec<Credential> = db
|
||||
@@ -156,28 +181,91 @@ impl WebAuthnService {
|
||||
.webauthn
|
||||
.generate_challenge_authenticate(credentials)
|
||||
.map_err(webauthn_error)?;
|
||||
let token = hex::encode(new_secret());
|
||||
self.challenges
|
||||
.lock()
|
||||
.map_err(|_| DomainError::Database("challenge lock poisoned".into()))?
|
||||
.authentications
|
||||
.insert(user_id, state);
|
||||
Ok(challenge)
|
||||
.insert(token.clone(), state);
|
||||
Ok((challenge, token))
|
||||
}
|
||||
|
||||
/// Finish a passkey authentication ceremony.
|
||||
/// Start a userless passkey authentication ceremony. No email is required:
|
||||
/// the authenticator selects a discoverable credential and returns a user
|
||||
/// handle that we resolve to the owning user on finish.
|
||||
pub async fn start_userless_authentication(
|
||||
&self,
|
||||
) -> DomainResult<(RequestChallengeResponse, String)> {
|
||||
let (challenge, mut state) = self
|
||||
.webauthn
|
||||
.generate_challenge_authenticate_options(vec![], None)
|
||||
.map_err(webauthn_error)?;
|
||||
// With no allowCredentials the browser will offer any discoverable
|
||||
// credential for this RP; the credential set is populated from the
|
||||
// user handle once the assertion is received.
|
||||
state.set_allowed_credentials(vec![]);
|
||||
let token = hex::encode(new_secret());
|
||||
self.challenges
|
||||
.lock()
|
||||
.map_err(|_| DomainError::Database("challenge lock poisoned".into()))?
|
||||
.authentications
|
||||
.insert(token.clone(), state);
|
||||
Ok((challenge, token))
|
||||
}
|
||||
|
||||
/// Finish a passkey authentication ceremony, resolving the owning user from
|
||||
/// the credential id (and, for userless ceremonies, the user handle).
|
||||
pub async fn finish_authentication(
|
||||
&self,
|
||||
user_id: i64,
|
||||
token: String,
|
||||
response: PublicKeyCredential,
|
||||
) -> DomainResult<()> {
|
||||
let state = self
|
||||
) -> DomainResult<i64> {
|
||||
let mut state = self
|
||||
.challenges
|
||||
.lock()
|
||||
.map_err(|_| DomainError::Database("challenge lock poisoned".into()))?
|
||||
.authentications
|
||||
.remove(&user_id)
|
||||
.remove(&token)
|
||||
.ok_or(DomainError::NotFound)?;
|
||||
|
||||
// For userless ceremonies the assertion carries a user handle that
|
||||
// identifies the user; load that user's credentials so the signature
|
||||
// can be verified against the correct key.
|
||||
if let Some(user_handle) = response.get_user_handle() {
|
||||
let handle = user_handle.to_vec();
|
||||
let users = Arc::clone(&self.users);
|
||||
let db = self.db.clone();
|
||||
let user_id = db
|
||||
.run(move |txn| {
|
||||
let users = users.clone();
|
||||
Box::pin(async move {
|
||||
let user = users
|
||||
.find_user_by_handle(txn, handle)
|
||||
.await?
|
||||
.ok_or(DomainError::NotFound)?;
|
||||
Ok(user.id)
|
||||
})
|
||||
})
|
||||
.await?;
|
||||
let passkeys = Arc::clone(&self.passkeys);
|
||||
let credentials: Vec<Credential> = db
|
||||
.run(move |txn| {
|
||||
let passkeys = passkeys.clone();
|
||||
Box::pin(async move {
|
||||
let rows = passkeys.list_for_user(txn, user_id).await?;
|
||||
let mut creds = Vec::new();
|
||||
for row in rows {
|
||||
let cred: Credential = serde_json::from_str(&row.credential)
|
||||
.map_err(|e| DomainError::Database(e.to_string()))?;
|
||||
creds.push(cred);
|
||||
}
|
||||
Ok(creds)
|
||||
})
|
||||
})
|
||||
.await?;
|
||||
state.set_allowed_credentials(credentials);
|
||||
}
|
||||
|
||||
let (cred_id, auth_data) = self
|
||||
.webauthn
|
||||
.authenticate_credential(&response, &state)
|
||||
@@ -189,28 +277,30 @@ impl WebAuthnService {
|
||||
let passkeys = Arc::clone(&self.passkeys);
|
||||
let db = self.db.clone();
|
||||
let credential_id_b64 = base64_url(cred_id);
|
||||
db.run(move |txn| {
|
||||
let passkeys = passkeys.clone();
|
||||
Box::pin(async move {
|
||||
let stored = passkeys
|
||||
.find_by_credential_id(txn, credential_id_b64)
|
||||
.await?
|
||||
.ok_or(DomainError::NotFound)?;
|
||||
let mut cred: Credential = serde_json::from_str(&stored.credential)
|
||||
.map_err(|e| DomainError::Database(e.to_string()))?;
|
||||
cred.counter = auth_data.counter;
|
||||
let serialized = serde_json::to_string(&cred)
|
||||
.map_err(|e| DomainError::Database(e.to_string()))?;
|
||||
sqlx::query("UPDATE passkeys SET credential = ?1 WHERE id = ?2")
|
||||
.bind(&serialized)
|
||||
.bind(stored.id)
|
||||
.execute(&mut *txn)
|
||||
.await
|
||||
.map_err(db_error)?;
|
||||
Ok(())
|
||||
let user_id = db
|
||||
.run(move |txn| {
|
||||
let passkeys = passkeys.clone();
|
||||
Box::pin(async move {
|
||||
let stored = passkeys
|
||||
.find_by_credential_id(txn, credential_id_b64)
|
||||
.await?
|
||||
.ok_or(DomainError::NotFound)?;
|
||||
let mut cred: Credential = serde_json::from_str(&stored.credential)
|
||||
.map_err(|e| DomainError::Database(e.to_string()))?;
|
||||
cred.counter = auth_data.counter;
|
||||
let serialized = serde_json::to_string(&cred)
|
||||
.map_err(|e| DomainError::Database(e.to_string()))?;
|
||||
sqlx::query("UPDATE passkeys SET credential = ?1 WHERE id = ?2")
|
||||
.bind(&serialized)
|
||||
.bind(stored.id)
|
||||
.execute(&mut *txn)
|
||||
.await
|
||||
.map_err(db_error)?;
|
||||
Ok(stored.user_id)
|
||||
})
|
||||
})
|
||||
})
|
||||
.await
|
||||
.await?;
|
||||
Ok(user_id)
|
||||
}
|
||||
|
||||
/// List the passkeys registered to a user.
|
||||
@@ -234,27 +324,6 @@ impl WebAuthnService {
|
||||
})
|
||||
.await
|
||||
}
|
||||
|
||||
/// Resolve the user id that owns the credential in an assertion response.
|
||||
pub async fn resolve_user_id_for_assertion(
|
||||
&self,
|
||||
response: &PublicKeyCredential,
|
||||
) -> DomainResult<i64> {
|
||||
let passkeys = Arc::clone(&self.passkeys);
|
||||
let db = self.db.clone();
|
||||
let credential_id_b64 = base64_url(&response.raw_id.0);
|
||||
db.run(move |txn| {
|
||||
let passkeys = passkeys.clone();
|
||||
Box::pin(async move {
|
||||
let stored = passkeys
|
||||
.find_by_credential_id(txn, credential_id_b64)
|
||||
.await?
|
||||
.ok_or(DomainError::NotFound)?;
|
||||
Ok(stored.user_id)
|
||||
})
|
||||
})
|
||||
.await
|
||||
}
|
||||
}
|
||||
|
||||
fn base64_url(bytes: &[u8]) -> String {
|
||||
|
||||
Reference in New Issue
Block a user