mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
Implement the device polling loop for Webauthn devices and apply it to tsh login. A separate package, lib/auth/webauthncli, is introduced to hold client-focused Webauthn logic. The separation highlights the distinction between server- and client-side code and isolates client-side dependencies from the existing lib/auth/webauthn. Includes improved test coverage for TeleportClient.Login (local logins only) and refactoring of existing code to support Webauthn challenges (PromptMFAChallenge logic has less branching and U2F device loop extracted and refactored into lib/auth/webauthncli). In terms of device compatibility, this is identical to the existing U2F solution- we are using the same underlying libraries and adapting the CTAP1 responses to Webauthn. This is easy to do and easy to reason about. I'm planning for a native Webauthn solution, such as libfido2, but that is larger change that doesn't seem to get us all the way to where we want for now (looking at you, Touch ID). * Add transformations and validations to lib/auth/webauthn * Implement client-side Webauthn login * Use RunOnU2FDevices in the lib/auth/u2f package This one is optional: it cuts a bit of the codebase today, but one could argue that it is safer to keep U2F untouched (up to the point where it gets removed). * Use CollectedClientData definition in lib/auth/mocku2f * Fix data race on auth.Server clock usage * Add direct test for TeleportClient.Login * Reply to Webauthn challenges on `tsh login`
25 lines
948 B
Go
25 lines
948 B
Go
// Copyright 2021 Gravitational, Inc
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
package webauthncli
|
|
|
|
// CollectedClientData is part of the data signed by authenticators
|
|
// (after marshaled to JSON, hashed and appended to authData).
|
|
// https://www.w3.org/TR/webauthn-2/#dictionary-client-data
|
|
type CollectedClientData struct {
|
|
Type string `json:"type"`
|
|
Challenge string `json:"challenge"`
|
|
Origin string `json:"origin"`
|
|
}
|