android / android/security-samples
Fido auth with Android SDK. Error from a server: invalid origin
- Dominant language
- Kotlin
- Stars
- 1k
- Forks
- 450
- PR merge metrics
- No merged PRs in 30d
Description
I use a FIDO android SDK https://developers.google.com/android/reference/com/google/android/gms/fido/package-summary and
web FIDO lib https://github.com/lbuchs/WebAuthn as a server
To complete authentication I send to the server the following payload:
```{"authenticatorData":"uGLTOEtQtBsB4wjhEvR0ZVayRWn/3mhUyp6dqFFY0a8BAAABDQ==","clientDataJSON":"eyJ0eXBlIjoid2ViYXV0aG4uZ2V0IiwiY2hhbGxlbmdlIjoiLW9zc3JiYXY3SmhmUWlQY1ZlMzFkdDQxMG5ZWHVvWW9kM1FYdHc5VmlIUSIsIm9yaWdpbiI6ImFuZHJvaWQ6YXBrLWtleS1oYXNoOmZiRU5UdkNTZVItQXdKVjVycnJCc2I5OHAtakV3MGM1U1NPTXVsX0t3YUkiLCJhbmRyb2lkUGFja2FnZU5hbWUiOiJjb20uYWZ0ZXJsb2dpYy5hdXJvcmEubWFpbCIsInRva2VuQmluZGluZyI6eyJzdGF0dXMiOiJwcmVzZW50IiwiaWQiOiJodHRwczpcL1wvdGVzdC5hZnRlcmxvZ2ljLmNvbSJ9fQ==","id":"LEBlQOlamqsmKzRBPQe9y0BFN5IaQ5BBB1ByiDH85HulzCYQTffqeK0RQDoZqUO7syGZY+hkfWf9P2FiQQ3eVA==","signature":"MEUCICFf8qFGiXxGTBokpstfUsCwbd7JTsLlDrFZoGMi3tZzAiEA0zAXxFDeqA7gF6YahudK+LD2gDUPtAnXqgAvvhVc/vE="}```
The field ```clientDataJSON``` contains a base64-encrypted JSON object that has property ```"origin":"android:apk-key-hash:fbENTvCSeR-AwJV5rrrBsb98p-jEw0c5SSOMul_KwaI"```
But the server responds with an error "invalid origin".
At the same time, my web FIDO auth implementation sends ```clientDataJSON``` with ```"origin":"https://test.afterlogic.com"``` and everything is working fine in this case.
How I can verify origin with android:apk-key-hash on the webserver? I will be appreciated any other ideas on how to deal with this.
Contributor guide
Research direction
Start by decoding the supplied clientDataJSON and compare its android:apk-key-hash origin with the origin validation used by the WebAuthn server. Read the linked Android FIDO SDK reference and the WebAuthn server documentation to determine whether this origin is supported and how it should be verified. Done means identifying a supported verification or documenting the incompatibility.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- android
- Domain
- authentication, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100