FeatureFuel
1

Passkeys: optional settings to let a passkey satisfy AAL2 and stand in for the current password

Source: supabase/supabase#51228 · opened by @DruidChiron
Summary With the new passkey support in Supabase Auth, a session established by signing in with a passkey is aal1 (AMR passkey), the same assurance level as a password sign-in. That is a sensible, conservative default. But there is currently no way for a project to choose otherwise, which has two consequences: 1. A user with a TOTP factor who signs in with a passkey is still asked for their TOTP code for anything that requires AAL2 (e.g. updateUser password change, managing passkeys while MFA is enabled). 2. With "Require current password when updating" enabled, a passkey cannot be used to re-authenticate. Only the current password is accepted, so a passkey-first user must keep a password solely to prove who they are when changing credentials. Observed behaviour Local Supabase CLI stack, supabase_flutter 2.18, Chrome on Windows 11, user with a verified TOTP factor and a registered passkey: • Sign in with the passkey → auth.sessions.aal = 'aal1'…

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests