mirror of
https://github.com/Sagit-chu/flvx.git
synced 2026-10-02 00:46:38 +08:00
861d61239a
Add WebAuthn passkey enrollment and login for issue #536, with trusted origin configuration, user verification, single-use challenges, and documented deployment and recovery behavior.
30 lines
1.1 KiB
Go
30 lines
1.1 KiB
Go
package handler
|
|
|
|
import (
|
|
"testing"
|
|
"time"
|
|
|
|
"github.com/go-webauthn/webauthn/webauthn"
|
|
)
|
|
|
|
func TestPasskeyChallengeExpiresAndIsSingleUse(t *testing.T) {
|
|
h := &Handler{passkeyPending: make(map[string]passkeyCeremony)}
|
|
id, ok := h.putPasskeyCeremony(passkeyCeremony{userID: 7, kind: "login", origin: "https://panel.example.test", session: webauthn.SessionData{Expires: time.Now().Add(time.Minute)}})
|
|
if !ok {
|
|
t.Fatal("could not create challenge")
|
|
}
|
|
if _, ok := h.takePasskeyCeremony(id, "login", "https://panel.example.test", 7); !ok {
|
|
t.Fatal("valid challenge was rejected")
|
|
}
|
|
if _, ok := h.takePasskeyCeremony(id, "login", "https://panel.example.test", 7); ok {
|
|
t.Fatal("challenge was reusable")
|
|
}
|
|
id, ok = h.putPasskeyCeremony(passkeyCeremony{userID: 7, kind: "login", origin: "https://panel.example.test", session: webauthn.SessionData{Expires: time.Now().Add(-time.Second)}})
|
|
if !ok {
|
|
t.Fatal("could not create expired challenge")
|
|
}
|
|
if _, ok := h.takePasskeyCeremony(id, "login", "https://panel.example.test", 7); ok {
|
|
t.Fatal("expired challenge was accepted")
|
|
}
|
|
}
|