Skip to content

01a0ee66 - Store the chosen passkey name as the account name and username - #338

Open
TaprootFreakAI wants to merge 3 commits into
developfrom
feat/01a0ee66-passkey-name
Open

TaprootFreakAI wants to merge 3 commits into
developfrom
feat/01a0ee66-passkey-name

Conversation

@TaprootFreakAI

Copy link
Copy Markdown
Collaborator

EN:
A new passkey account can be given a name at registration. That lowercase name is the passkey label, the account name, and the username. Requests without a name still create an unnamed account, and the account id stays a server-generated UUID.

DE:
Ein neues Passkey-Konto kann bei der Registrierung einen Namen bekommen. Dieser kleingeschriebene Name ist die Passkey-Bezeichnung, der Kontoname und der Benutzername. Anfragen ohne Namen legen weiter ein namenloses Konto an, und die Konto-ID bleibt eine vom Server erzeugte UUID.

Details

POST /auth/passkey/register/begin accepts an optional name. The value is normalized with the username rules (1–32 characters of a-z, 0-9, hyphen, underscore, or dot, stored lowercase). An invalid name is rejected before a challenge is stored. A name that is already taken is rejected as well. On success the normalized name is kept on the challenge and copied into the WebAuthn user name and display name, so the device shows that label. Finish writes the same string to account.name and account.username.

An empty body keeps the previous behavior: the passkey label is the new account id and the account has no name yet. A claim with viewKey ignores name. Login does not read the label.

The register begin request may include a name. The same lowercase
handle becomes the passkey label, the account name, and the username.
A request without a name still creates an unnamed account, and the
account id stays a server-generated UUID.
@TaprootFreakAI

Copy link
Copy Markdown
Collaborator Author

EN:
Ready after 3 review passes.
A chosen name at passkey registration becomes the passkey label, the account name, and the username.

DE:
Bereit nach 3 Review-Durchläufen.
Ein bei der Passkey-Registrierung gewählter Name wird zur Passkey-Bezeichnung, zum Kontonamen und zum Benutzernamen.

Details

The first pass asked for the debug challenge field, the function-handbook outcomes, the nullable column on an existing database, and the route contract for the optional name. Those are in this pull request.

The second pass asked to stop describing every body without a name as a new account. A body that carries a view key claims a provisioned account and does not mint an id. The contract sentence now says that.

The third pass found nothing to change.

No review comments are open. The branch merges cleanly into develop. The pull-request check on this commit succeeded.

@TaprootFreakAI
TaprootFreakAI marked this pull request as ready for review September 29, 2026 22:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant