Skip to content

implement fido 2fa - #383

Open
freswa wants to merge 1 commit into
doy:mainfrom
freswa:fido
Open

freswa wants to merge 1 commit into
doy:mainfrom
freswa:fido

Conversation

@freswa

@freswa freswa commented Oct 7, 2026

Copy link
Copy Markdown

This has been tested against vaultwarden.

fixes #156

pschmitt added a commit to pschmitt/rbw that referenced this pull request Oct 7, 2026
Port of Frederik Schwan's upstream PR "implement fido 2fa"
(doy#383, commit 2183b8e), adapted to this
fork:

- parse TwoFactorProviders2 and keep the WebAuthn (type 7) challenge on
  Error::TwoFactorRequired
- new optional `fido2` cargo feature (Mozilla's `authenticator` crate);
  rbw-agent signs the challenge with a security key, prompting for the
  key's PIN via pinentry, and streams Response::Progress messages that
  the client prints while it waits for the final response
- fork adaptations: per-account ui_url, the fork's pinentry
  cancel/timeout plumbing, the reworked interactive login flow
- packaging: Nix package enables `fido2` (pkg-config + udev); CI and
  justfile musl builds stay on default features, Linux all-features jobs
  install libudev-dev; deny.toml skips authenticator's older crypto deps
  and ignores the serde_cbor unmaintained advisory

The upstream PR's unrelated clippy-style cleanups were already in this
fork or are left out.

Co-authored-by: Frederik Schwan <frederik@tty42.de>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YTm1GQVoyjsteymHPCRW75
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support FIDO2 WebAuthn 2FA

1 participant