YubiKey + Webauth:userHandle 始终为 null

sim*_*bro 1 security webauthn yubikey

当我使用 WebAuthn 和 YubiKey 进行身份验证时, response.userHandle 属性始终为空。那是我注册凭据的用户 id 和 displayName 不会返回。这是因为我在注册/身份验证过程中做错了什么:

async function register() {
  const publicKeyCredentialCreationOptions = {
    challenge: Uint8Array.from("this-is-a-test", (c) => c.charCodeAt(0)),
    rp: {
      name: "Webauthn Test",
      id: "localhost",
    },
    user: {
      id: Uint8Array.from("a1b2c3d4e5f6", (c) => c.charCodeAt(0)),
      name: "just-a-test",
      displayName: "MrUser",
    },
    pubKeyCredParams: [{ alg: -7, type: "public-key" }],
    authenticatorSelection: {
      authenticatorAttachment: "cross-platform",
    },
    timeout: 60000,
    attestation: "direct",
  };

  const credential = await navigator.credentials.create({
    publicKey: publicKeyCredentialCreationOptions,
  });
}
Run Code Online (Sandbox Code Playgroud)

这是我用来验证的代码:

async function authenticate() {
  const publicKeyCredentialRequestOptions = {
    challenge: Uint8Array.from("test", (c) => c.charCodeAt(0)),
    allowCredentials: [
      {
        id: credentialId,
        type: "public-key",
        transports: ["usb", "ble", "nfc"],
      },
    ],
    timeout: 60000,
  };

  const assertion = await navigator.credentials.get({
    publicKey: publicKeyCredentialRequestOptions,
  });

  console.log(assertion);
}
Run Code Online (Sandbox Code Playgroud)

我最终得到的是:

{
  rawId: ArrayBuffer(64),
  id: "U-nitqhlORmmdltp7TLO3i18KNoWsSebFyrtc3OIRvcktvwlz-dJZCA1_1gxXrNHzqReU7xGAHdfVP75N2aJSw", 
  response: {
    authenticatorData: ArrayBuffer(37) {}
    clientDataJSON: ArrayBuffer(101) {}
    signature: ArrayBuffer(71) {}
    userHandle: null
  }
  type: "public-key"
}

As you can see: userHandle is null.  Can anyone tell me why?
Run Code Online (Sandbox Code Playgroud)

Luk*_*ker 6

将userHandle取决于哪种类型的WebAuthn的证书依赖方可以为空请求被创建。

默认的 WebAuthn 行为将创建一个不可发现的凭据,并且userHandle断言中返回的值为 null。对于这种类型的凭证,认证器上没有存储任何数据,因此没有什么可返回的。

要创建 WebAuthn 客户端可发现凭据,也就是常驻密钥,您必须将requireResidentKey成员设置为true. 这将在身份验证器上存储凭据数据,并将userHandle在断言中返回。有关详细信息,请参阅W3C WebAuthn 规范中的AuthenticatorSelectionCriteria。

下面是一个例子:

authenticatorSelection: {
  authenticatorAttachment: "cross-platform",
  requireResidentKey: true
},
Run Code Online (Sandbox Code Playgroud)

请参阅Yubico 的 WebAuthn 开发指南以了解有关常驻密钥和userHandle 的更多信息。