14e9db606a03699262975461993d3058401e4069
The missing /me/step-up/webauthn/begin and /finish were a plan defect, not an acceptable gap: a user whose only factor is a passkey was offered only recovery codes for step-up, burning one every ten minutes. Adds the handlers in package auth (session-authenticated, not themselves behind RequireStepUp, modeled on HandleMFAWebAuthnBegin/finishAssertion) and registers both routes behind the same RateLimitAuth() as /me/step-up. StepUpModal now offers "Use passkey" when the server names webauthn and the browser supports WebAuthn.
Description
No description provided
9.7 MiB
Languages
JavaScript
63.9%
Go
19.3%
TypeScript
16.6%