From 0a76a28870abbb3431c76824d0be7c4da380ed22 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Filip=20=C5=9Al=C4=99zak?= Date: Tue, 15 Sep 2026 19:38:31 +0200 Subject: [PATCH 1/2] fido2 setup --- common/client_types.proto | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/common/client_types.proto b/common/client_types.proto index 790e31d..dc17b01 100644 --- a/common/client_types.proto +++ b/common/client_types.proto @@ -382,12 +382,22 @@ message CodeMfaSetupStartRequest { // in case of email secret is empty message CodeMfaSetupStartResponse { optional string totp_secret = 1; + // [2.2] For FIDO2: the WebAuthn CreationChallengeResponse, JSON-encoded as + // webauthn-rs serializes it. The client feeds it to the authenticator and + // returns the resulting attestation in CodeMfaSetupFinishRequest. + optional string fido2_creation_challenge = 2; } message CodeMfaSetupFinishRequest { + // Empty for FIDO2, whose proof is the attestation below rather than a code. string code = 1; string token = 2; MfaMethod method = 3; + // [2.2] For FIDO2: the name to store the new security key under. + optional string name = 4; + // [2.2] For FIDO2: the WebAuthn RegisterPublicKeyCredential attestation, + // JSON-encoded as webauthn-rs serializes it. + optional string fido2_attestation = 5; } message CodeMfaSetupFinishResponse { @@ -423,6 +433,8 @@ message MfaConfigAuthorizeRequest { message MfaConfigAuthorizeResponse { int64 deadline_timestamp = 1; + // Recovery codes, populated only when the email fallback enables the email factor. + repeated string recovery_codes = 2; } // External OIDC authentication flow From 13331198c7ec8d72d85c7b32521bda5cd4cf96f8 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Filip=20=C5=9Al=C4=99zak?= Date: Fri, 18 Sep 2026 09:51:15 +0200 Subject: [PATCH 2/2] revise comments --- common/client_types.proto | 13 +++++-------- 1 file changed, 5 insertions(+), 8 deletions(-) diff --git a/common/client_types.proto b/common/client_types.proto index dc17b01..808439b 100644 --- a/common/client_types.proto +++ b/common/client_types.proto @@ -382,21 +382,18 @@ message CodeMfaSetupStartRequest { // in case of email secret is empty message CodeMfaSetupStartResponse { optional string totp_secret = 1; - // [2.2] For FIDO2: the WebAuthn CreationChallengeResponse, JSON-encoded as - // webauthn-rs serializes it. The client feeds it to the authenticator and - // returns the resulting attestation in CodeMfaSetupFinishRequest. + // [2.2] WebAuthn CreationChallengeResponse, JSON as serialized by webauthn-rs. optional string fido2_creation_challenge = 2; } message CodeMfaSetupFinishRequest { - // Empty for FIDO2, whose proof is the attestation below rather than a code. + // Empty for FIDO2, proven by fido2_attestation instead. string code = 1; string token = 2; MfaMethod method = 3; - // [2.2] For FIDO2: the name to store the new security key under. + // [2.2] FIDO2 security key name. optional string name = 4; - // [2.2] For FIDO2: the WebAuthn RegisterPublicKeyCredential attestation, - // JSON-encoded as webauthn-rs serializes it. + // [2.2] WebAuthn RegisterPublicKeyCredential, JSON as serialized by webauthn-rs. optional string fido2_attestation = 5; } @@ -433,7 +430,7 @@ message MfaConfigAuthorizeRequest { message MfaConfigAuthorizeResponse { int64 deadline_timestamp = 1; - // Recovery codes, populated only when the email fallback enables the email factor. + // Populated only when the email fallback enables the email factor. repeated string recovery_codes = 2; }