Browse Source

Restrict webauthn to fingerprint only

pull/161/head
Matthias Frey 4 years ago
parent
commit
473fa17365
  1. 5
      apps/api/src/app/auth/web-auth.service.ts

5
apps/api/src/app/auth/web-auth.service.ts

@ -57,7 +57,8 @@ export class WebAuthService {
timeout: 60000, timeout: 60000,
attestationType: 'indirect', attestationType: 'indirect',
authenticatorSelection: { authenticatorSelection: {
userVerification: 'preferred', authenticatorAttachment: 'platform',
userVerification: 'required',
requireResidentKey: false requireResidentKey: false
} }
}; };
@ -143,7 +144,7 @@ export class WebAuthService {
{ {
id: device.credentialId, id: device.credentialId,
type: 'public-key', type: 'public-key',
transports: ['usb', 'ble', 'nfc', 'internal'] transports: ['internal']
} }
], ],
userVerification: 'preferred', userVerification: 'preferred',

Loading…
Cancel
Save