01a0e81d - Return the owner account from seed finish and log bad passkey JSON - #336
Merged
Merged
Conversation
The app reads this 200 body as the account itself. The extra account wrapper made that read fail, so the twelve words never appeared after the passkey was stored.
TaprootFreakAI
marked this pull request as ready for review
September 29, 2026 14:09
TaprootFreakAI
marked this pull request as draft
September 29, 2026 19:02
A finish body that is not JSON, missing, or not challengeId plus credential is stored as a diagnostic row. The raw body, credential, token, and view key are not. Seed failures after a known session include the account id.
Collaborator
Author
|
EN: DE: DetailsThe first pass found the same seed-begin failure logged twice. That second write is gone. The next pass found a test that searched the whole log line for the digits 12, which also appear in the timestamp. The test now expects the log object exactly, with the timestamp only as a string. No open review threads. The pull request merges cleanly. On this head the check is green: typecheck, lint, handbook, e2e completeness, tests at full coverage, Postgres, build, and e2e. |
TaprootFreakAI
marked this pull request as ready for review
September 29, 2026 20:48
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
EN:
Passkey seed finish still returns the owner account itself, the same shape as GET /me. Login is unchanged.
A finish body that is missing, not JSON, or not challengeId plus credential is stored as a diagnostic row before the 400.
Invalid JSON is reported as "Finish body is not valid JSON". The raw body, credential, token, and view key are not stored.
A seed failure after the session is known includes the account id.
DE:
Passkey-Seed-Finish liefert weiter das Konto selbst, in derselben Form wie GET /me. Die Anmeldung bleibt unverändert.
Ein Finish-Body, der fehlt, kein JSON ist oder nicht challengeId plus credential enthält, wird vor dem 400 als Diagnosezeile gespeichert.
Ungültiges JSON meldet "Finish body is not valid JSON". Rohtext, Credential, Token und View-Key werden nicht gespeichert.
Ein Seed-Fehler nach bekannter Sitzung enthält die Konto-Id.
Details
POST /auth/passkey/seed/finishstill returns the owner account itself, with notokenand noaccountwrapper.z.unknown()accepts a missingcredentialkey, so a body that only haschallengeIdused to pass schema checks and was logged as an unknown challenge. That case is now the expected-body 400. Invalid JSON is a separate 400,Finish body is not valid JSON. Register begin with invalid JSON isBegin body is not valid JSONand does not open a challenge. An empty begin body still starts registration.The diagnostic row stores
error,bodyBytes, andjson(absent,invalid, orparsed). A parsed object also storesbodyKind,hasCredential, andchallengeIdKind. The challenge id is stored only when it is 64 lowercase hex. Seed begin 409 and later seed ceremony failures storeauth.passkey.seed.failwith the account id, and the failed renew row is unchanged. A 401 on seed or replace stores no diagnostic row and no renew row, so a bearer is never written. Unconfigured WebAuthn still logs the 500 with no account id.