BeyondCodeBootcamp / BeyondCodeBootcamp/passkeys

Thoughts on UX

Đang mở
#3 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
JavaScript
Star
2
Fork
1
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

## Forgot Passkey

- instead of "Forgot Password?" have "Can't Access Passkey?"

## Replace Passkey

- this will make any encrypted storage permanently inaccessible

## Adding a Passkey

- send magic email or text message to allow it
- use password to allow it? maybe not?
- allow creating password if the device doesn't support WebAuthn at all

## Boolean IDs

IDs are a huge pain in the butt:
- the os keychain may or may not be synced between devices
- the current device may or may not have synced with the os keychain
- the current browser on that device may or may not access the system keychain
- the current browser may or may not be synced with its own key storage
- if you've saved IDs to the server, you can't use them as entropy for local encryption
- you can't retrieve IDs from the server without the user ALREADY being logged in \
(otherwise anyone can just grab bunches of IDs for your users, or you have waaay more logic to handle in regards to fingerprinting the user's devices and browsers, etc to ensure that you don't pass them out willy-nilly)
- the IDs are only useful to prevent creation of the same ID, which you get by logging in - otherwise, if you had them, you would already know

THEREFORE, it seems like each device should just have some sort of localStorage that simply indicates a tiny piece of information about each key - such as if the "attestation" issuer is a security key or os keycahin, etc.

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Hướng nghiên cứu

Không có tệp, bài kiểm thử hoặc entry point nào được nêu. Trước tiên, lập bản đồ các luồng passkey và khôi phục tài khoản hiện có, sau đó giải quyết các đề xuất liên quan đến passkey bị quên, bị thay thế và mới được thêm vào, bao gồm cả các mối lo ngại về Boolean ID và local-storage. Chỉ được xem là hoàn tất khi đã thống nhất thiết kế UX và bảo mật trước khi triển khai.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
javascript
Lĩnh vực
authentication, security
Loại issue
Tính năng
Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Cần làm rõ
Mức phù hợp với người mới
20/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.