Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Passkey Helper: 1Password/WebAuthn fails from content script — working solution using MAIN world + service worker

Đang mở
#173 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 5 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
48/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
go, javascript

Hướng nghiên cứu

Bắt đầu bằng việc xem xét extension đã sửa được đính kèm, đặc biệt là background.js, content.js và webauthn-main.js, rồi so sánh với triển khai Passkey Helper hiện có. Tái hiện luồng passkey của WhatsApp Web trong Chrome với 1Password, kiểm tra lệnh gọi WebAuthn trong MAIN-world và việc giao tiếp với API của service-worker. Hoàn tất khi ghép nối thành công mà không xuất hiện lời nhắc về khóa bảo mật vật lý hoặc lỗi fetch CSP.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

bug
Welcome!
  • Yes, I have searched for similar issues on GitHub and found none.
What did you do?

Description

I found and successfully tested a fix for the Evolution GO Passkey Helper when using 1Password with Google Chrome.

In my environment, the original Passkey Helper correctly detected the Evolution GO passkey ceremony, but when I clicked the authentication button Chrome did not offer the passkey stored in 1Password.

Instead, Chrome displayed:

"Insert your security key and touch it"

as if a physical USB/FIDO security key was required.

The same WhatsApp passkey worked normally with 1Password when authentication was initiated directly by WhatsApp Web, so the passkey itself and the 1Password integration were working correctly.

What I found

The WebAuthn call:

navigator.credentials.get()

was being executed from the extension content script.

I tested moving the script to "world": "MAIN". This changed the behavior, but then WhatsApp Web's Content Security Policy blocked requests from the page context to the Evolution GO /passkey-ceremony/... endpoint.

Chrome reported a connect-src CSP violation and the helper returned Failed to fetch.

Working solution

I separated the extension into three parts:

background.js
Performs HTTP requests to the Evolution GO /passkey-ceremony/... API.
This avoids WhatsApp Web's CSP restriction.
content.js
Handles the helper UI, ceremony polling and communication between the extension contexts.
webauthn-main.js
Runs on web.whatsapp.com using "world": "MAIN".
Performs only the WebAuthn operation (navigator.credentials.get()).
It does not perform external HTTP requests.

Communication between the content script and MAIN-world script is used to return the WebAuthn assertion, while the extension service worker communicates with Evolution GO.

I also avoid forcing credential transports and omit allowCredentials when Evolution GO returns an empty array, allowing the browser/password manager to select the appropriate authenticator.

Result

After this change the complete flow worked:

Evolution GO → WhatsApp passkey challenge → Chrome → 1Password → WebAuthn assertion → Evolution GO → WhatsApp connected successfully.

The instance successfully paired and connected.

Environment
Evolution GO: evoapicloud/evolution-go:latest
Google Chrome
Linux
1Password browser extension
WhatsApp account requiring passkey authentication
Evolution GO behind HTTPS/reverse proxy

I have a working modified extension and can provide the source code or open a PR if the maintainers are interested.

evolution-go-passkey-helper-community.zip

What did you expect?

.

What did you observe instead of what you expected?

.

Screenshots/Videos

.

Which version are you using?

.

What is your environment?

Linux

If applicable, paste the log output

.

Additional Notes

Development note

I used ChatGPT (OpenAI) to help analyze the original Evolution GO Passkey Helper implementation and troubleshoot the WebAuthn behavior.

Through testing, we identified the difference between running navigator.credentials.get() from the extension's isolated content-script context and from the web.whatsapp.com MAIN world, as well as the CSP issue that occurred when the entire helper was moved to the MAIN world.

ChatGPT then helped me develop an alternative implementation that separates the WebAuthn operation from the Evolution GO API communication, specifically to make the authentication flow work correctly with 1Password.

I tested the resulting extension in my own environment, and the complete WhatsApp pairing process succeeded.

Ngôn ngữ chính
Go
Star
890
Fork
473
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

  • Có Dockerfile hoặc tệp Docker Compose
  • Có mẫu pull request
  • Không có hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của evolution-foundation/evolution-go

Tất cả issue của evolution-foundation/evolution-go

Issue tương tự

Thêm issue về Go

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.