Class: SecondFactorWebauthnCredentialsController
- Inherits:
-
ApplicationController
- Object
- ApplicationController
- SecondFactorWebauthnCredentialsController
- Defined in:
- lib/generators/webauthn_authentication/templates/app/controllers/second_factor_webauthn_credentials_controller.rb
Instance Method Summary collapse
Instance Method Details
#create ⇒ Object
20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 |
# File 'lib/generators/webauthn_authentication/templates/app/controllers/second_factor_webauthn_credentials_controller.rb', line 20 def create webauthn_credential = WebAuthn::Credential.from_create(JSON.parse(create_credential_params[:public_key_credential])) begin webauthn_credential.verify( session[:current_registration][:challenge] || session[:current_registration]["challenge"] ) credential = Current.user.second_factor_webauthn_credentials.find_or_initialize_by( external_id: webauthn_credential.id ) if credential.update( nickname: create_credential_params[:nickname], public_key: webauthn_credential.public_key, sign_count: webauthn_credential.sign_count ) redirect_to root_path, notice: "Security Key registered successfully" else redirect_to new_second_factor_webauthn_credential_path, alert: "Error registering credential" end rescue WebAuthn::Error => e redirect_to new_second_factor_webauthn_credential_path, alert: "Verification failed: #{e.}" end ensure session.delete(:current_registration) end |
#create_options ⇒ Object
2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 |
# File 'lib/generators/webauthn_authentication/templates/app/controllers/second_factor_webauthn_credentials_controller.rb', line 2 def = WebAuthn::Credential.( user: { id: Current.user.webauthn_id, name: Current.user.email_address }, exclude: Current.user.webauthn_credentials.pluck(:external_id), authenticator_selection: { resident_key: "discouraged", user_verification: "discouraged" } ) session[:current_registration] = { challenge: .challenge } render json: end |
#destroy ⇒ Object
48 49 50 51 52 |
# File 'lib/generators/webauthn_authentication/templates/app/controllers/second_factor_webauthn_credentials_controller.rb', line 48 def destroy Current.user.second_factor_webauthn_credentials.destroy(params[:id]) redirect_to root_path, notice: "Security Key deleted successfully" end |