Thoughts on UX
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 20/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Stale
- Tech stack
- javascript
- Domain
- authentication, security
Research direction
No files, tests, or entry points are named. First map the existing passkey and account-recovery flows, then resolve the proposals around forgotten, replaced, and newly added passkeys, including the Boolean ID and local-storage concerns. Done requires an agreed UX and security design before implementation.
Written by the indexing model from the issue text.
Description
Forgot Passkey
- instead of "Forgot Password?" have "Can't Access Passkey?"
Replace Passkey
- this will make any encrypted storage permanently inaccessible
Adding a Passkey
- send magic email or text message to allow it
- use password to allow it? maybe not?
- allow creating password if the device doesn't support WebAuthn at all
Boolean IDs
IDs are a huge pain in the butt:
- the os keychain may or may not be synced between devices
- the current device may or may not have synced with the os keychain
- the current browser on that device may or may not access the system keychain
- the current browser may or may not be synced with its own key storage
- if you've saved IDs to the server, you can't use them as entropy for local encryption
- you can't retrieve IDs from the server without the user ALREADY being logged in
(otherwise anyone can just grab bunches of IDs for your users, or you have waaay more logic to handle in regards to fingerprinting the user's devices and browsers, etc to ensure that you don't pass them out willy-nilly) - the IDs are only useful to prevent creation of the same ID, which you get by logging in - otherwise, if you had them, you would already know
THEREFORE, it seems like each device should just have some sort of localStorage that simply indicates a tiny piece of information about each key - such as if the "attestation" issuer is a security key or os keycahin, etc.
- Dominant language
- JavaScript
- Stars
- 2
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from BeyondCodeBootcamp/passkeys
-
Difficulty 2/5 1-3 hours Newbie friendliness 25/100
-
Difficulty 3/5 1-2 days Newbie friendliness 35/100
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
-
Difficulty 4/5 3-5 days Newbie friendliness 25/100
-
Difficulty 4/5 3-5 days Newbie friendliness 28/100
BeyondCodeBootcamp/passkeys#6 · 1 comment ·
All issues in BeyondCodeBootcamp/passkeys
Similar issues
-
bug confirmed issue
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
open-webui/open-webui#30750 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Mend: dependency security vulnerability untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 70/100