Skip to content

01a0e81d - Return the owner account from seed finish and log bad passkey JSON - #336

Merged
TaprootFreak merged 4 commits into
developfrom
fix/01a0e81d-seed-finish-body
Sep 30, 2026
Merged

TaprootFreak merged 4 commits into
developfrom
fix/01a0e81d-seed-finish-body

Conversation

@TaprootFreakAI

@TaprootFreakAI TaprootFreakAI commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

EN:
Passkey seed finish still returns the owner account itself, the same shape as GET /me. Login is unchanged.
A finish body that is missing, not JSON, or not challengeId plus credential is stored as a diagnostic row before the 400.
Invalid JSON is reported as "Finish body is not valid JSON". The raw body, credential, token, and view key are not stored.
A seed failure after the session is known includes the account id.

DE:
Passkey-Seed-Finish liefert weiter das Konto selbst, in derselben Form wie GET /me. Die Anmeldung bleibt unverändert.
Ein Finish-Body, der fehlt, kein JSON ist oder nicht challengeId plus credential enthält, wird vor dem 400 als Diagnosezeile gespeichert.
Ungültiges JSON meldet "Finish body is not valid JSON". Rohtext, Credential, Token und View-Key werden nicht gespeichert.
Ein Seed-Fehler nach bekannter Sitzung enthält die Konto-Id.

Details

POST /auth/passkey/seed/finish still returns the owner account itself, with no token and no account wrapper.

z.unknown() accepts a missing credential key, so a body that only has challengeId used to pass schema checks and was logged as an unknown challenge. That case is now the expected-body 400. Invalid JSON is a separate 400, Finish body is not valid JSON. Register begin with invalid JSON is Begin body is not valid JSON and does not open a challenge. An empty begin body still starts registration.

The diagnostic row stores error, bodyBytes, and json (absent, invalid, or parsed). A parsed object also stores bodyKind, hasCredential, and challengeIdKind. The challenge id is stored only when it is 64 lowercase hex. Seed begin 409 and later seed ceremony failures store auth.passkey.seed.fail with the account id, and the failed renew row is unchanged. A 401 on seed or replace stores no diagnostic row and no renew row, so a bearer is never written. Unconfigured WebAuthn still logs the 500 with no account id.

The app reads this 200 body as the account itself. The extra account
wrapper made that read fail, so the twelve words never appeared after
the passkey was stored.
@TaprootFreakAI
TaprootFreakAI marked this pull request as ready for review September 29, 2026 14:09
@TaprootFreakAI
TaprootFreakAI marked this pull request as draft September 29, 2026 19:02
A finish body that is not JSON, missing, or not challengeId plus
credential is stored as a diagnostic row. The raw body, credential,
token, and view key are not. Seed failures after a known session
include the account id.
@TaprootFreakAI TaprootFreakAI changed the title 01a0e81d - Return the owner account from passkey seed finish 01a0e81d - Return the owner account from seed finish and log bad passkey JSON Sep 29, 2026
@TaprootFreakAI

Copy link
Copy Markdown
Collaborator Author

EN:
Ready after 3 review passes.
Passkey seed finish returns the owner account itself, and a bad body is logged without secrets.

DE:
Bereit nach 3 Review-Durchläufen.
Seed-Finish liefert das Konto selbst, und ein ungültiger Body wird ohne Geheimnisse protokolliert.

Details

The first pass found the same seed-begin failure logged twice. That second write is gone. The next pass found a test that searched the whole log line for the digits 12, which also appear in the timestamp. The test now expects the log object exactly, with the timestamp only as a string.

No open review threads. The pull request merges cleanly. On this head the check is green: typecheck, lint, handbook, e2e completeness, tests at full coverage, Postgres, build, and e2e.

@TaprootFreakAI
TaprootFreakAI marked this pull request as ready for review September 29, 2026 20:48
@TaprootFreak
TaprootFreak merged commit b3a6678 into develop Sep 30, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants