Skip to content

fix(passkeys): enforce AAL checks on passkey registration and deletion#2565

Merged
fadymak merged 1 commit into
masterfrom
fm/auth-1227
Jun 5, 2026
Merged

fix(passkeys): enforce AAL checks on passkey registration and deletion#2565
fadymak merged 1 commit into
masterfrom
fm/auth-1227

Conversation

@fadymak

@fadymak fadymak commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

If a user has a verified MFA factor enrolled, then enforce AAL2 for passkey registration and deletion.

Note: we explicitly do not gate the passkey update operation since it can only be used to update the friendly_name of the passkey.

@fadymak fadymak requested a review from a team as a code owner June 4, 2026 15:19

@cstockton cstockton left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me 👍 🚀

@fadymak fadymak merged commit 7e6f2e4 into master Jun 5, 2026
11 checks passed
@fadymak fadymak deleted the fm/auth-1227 branch June 5, 2026 09:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants