01a0ee66 - Store the chosen passkey name as the account name and username - #338
TaprootFreakAI wants to merge 3 commits into
Conversation
The register begin request may include a name. The same lowercase handle becomes the passkey label, the account name, and the username. A request without a name still creates an unnamed account, and the account id stays a server-generated UUID.
|
EN: DE: DetailsThe first pass asked for the debug challenge field, the function-handbook outcomes, the nullable column on an existing database, and the route contract for the optional name. Those are in this pull request. The second pass asked to stop describing every body without a name as a new account. A body that carries a view key claims a provisioned account and does not mint an id. The contract sentence now says that. The third pass found nothing to change. No review comments are open. The branch merges cleanly into develop. The pull-request check on this commit succeeded. |
EN:
A new passkey account can be given a name at registration. That lowercase name is the passkey label, the account name, and the username. Requests without a name still create an unnamed account, and the account id stays a server-generated UUID.
DE:
Ein neues Passkey-Konto kann bei der Registrierung einen Namen bekommen. Dieser kleingeschriebene Name ist die Passkey-Bezeichnung, der Kontoname und der Benutzername. Anfragen ohne Namen legen weiter ein namenloses Konto an, und die Konto-ID bleibt eine vom Server erzeugte UUID.
Details
POST /auth/passkey/register/beginaccepts an optionalname. The value is normalized with the username rules (1–32 characters of a-z, 0-9, hyphen, underscore, or dot, stored lowercase). An invalid name is rejected before a challenge is stored. A name that is already taken is rejected as well. On success the normalized name is kept on the challenge and copied into the WebAuthn user name and display name, so the device shows that label. Finish writes the same string toaccount.nameandaccount.username.An empty body keeps the previous behavior: the passkey label is the new account id and the account has no name yet. A claim with
viewKeyignoresname. Login does not read the label.