Repository navigation
Security: server-side WebAuthn challenges; verify gateway TLS in the CLI - #23
ndbroadbent wants to merge 1 commit into
Conversation
WebAuthn (server): - Challenges used to round-trip through the client as session_data and were trusted on the way back. One captured assertion could be replayed as a step-up proof indefinitely, and a zeroed Expires skipped go-webauthn's expiry check. - Challenges now live in a webauthn_challenges table, bound to the user and the session that started the ceremony. They are single-use (DELETE ... RETURNING), expire after a few minutes, and the client only gets an opaque ID back in the same session_data field. This covers login MFA, step-up, inline WebAuthn on the proxy, and enrollment. - The credential sign counter is stored and enforced (clone detection). CLI: - Every proxied Convox command went through stdsdk's http.Client and websocket dialer, which set InsecureSkipVerify. A man-in-the-middle with any certificate got the session token and MFA proof from the Basic auth header. Both now verify certificates against the system roots, and plain http:// is refused except for loopback gateways. - The rack-proxy URL's credentials are URL-encoded, so inline WebAuthn data can't break parsing (the parse error used to echo the token). - Inline step-up WebAuthn derives the RP ID from the configured gateway host and rejects a different RP ID sent by the server.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| JavaScript | Oct 9, 2026 5:03a.m. | Review ↗ | |
| Go | Oct 9, 2026 5:03a.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
This PR is stacked on #19. It fixes RG-11 (MFA-4, CLI-1, CLI-10, MFA-13) from the 2026-10-09 audit.
WebAuthn (server)
session_data, and the server trusted whatever came back:Expiresskipped go-webauthn's expiry check.webauthn_challengestable.DELETE … RETURNING) and expires after a few minutes.session_datafield, so the SPA needs no change.CLI
InsecureSkipVerifyset. Anyone able to intercept the connection could capture the session token and MFA proof.http://is refused except for loopback gateways.Testing
task go:test,task web:test, lint and duplication checks: all passMigration:
20261009120000_webauthn_challenges.sql