Skip to content

Validate userHandle from authenticator response against webauthn_id#131

Merged
santiagorodriguez96 merged 4 commits intomasterfrom
sr--validate-user-handle
Mar 18, 2026
Merged

Validate userHandle from authenticator response against webauthn_id#131
santiagorodriguez96 merged 4 commits intomasterfrom
sr--validate-user-handle

Conversation

@santiagorodriguez96
Copy link
Copy Markdown
Collaborator

Fixes #121.

Comment thread lib/devise/strategies/passkey_authenticatable.rb
Comment thread lib/devise/strategies/webauthn_two_factor_authenticatable.rb
Comment thread lib/devise/strategies/passkey_authenticatable.rb
@santiagorodriguez96 santiagorodriguez96 merged commit 8fe5640 into master Mar 18, 2026
25 checks passed
@santiagorodriguez96 santiagorodriguez96 deleted the sr--validate-user-handle branch March 18, 2026 20:10
@RenzoMinelli RenzoMinelli mentioned this pull request Apr 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

userHandle from authenticator response is not validated against stored webauthn_id

2 participants