1
Passkeys: optional settings to let a passkey satisfy AAL2 and stand in for the current password
Source: supabase/supabase#51228 · opened by @DruidChiron
Summary With the new passkey support in Supabase Auth, a session established by signing in with a passkey is aal1 (AMR passkey), the same assurance level as a password sign-in. That is a sensible, conservative default. But there is currently no way for a project to choose otherwise, which has two consequences: 1. A user with a TOTP factor who signs in with a passkey is still asked for their TOTP code for anything that requires AAL2 (e.g. updateUser password change, managing passkeys while MFA is enabled). 2. With "Require current password when updating" enabled, a passkey cannot be used to re-authenticate. Only the current password is accepted, so a passkey-first user must keep a password solely to prove who they are when changing credentials. Observed behaviour Local Supabase CLI stack, supabase_flutter 2.18, Chrome on Windows 11, user with a verified TOTP factor and a registered passkey: • Sign in with the passkey → auth.sessions.aal = 'aal1'…
No pledges yet. Be the first to back this.
Comments
Similar requests
Auth: Auto-enforce AAL2 at API gateway level for MFA-enrolled users
1 vote · 0 comments
OAuth 2.1 server: no way to require MFA (aal2) for OAuth client access tokens
1 vote · 0 comments
Support for passkeys in Supabase Auth
285 votes · 0 comments
Handling the Password Reset for a user by Supabase itself.
2 votes · 0 comments
Password reset should not act as OTP
3 votes · 0 comments
No comments yet.