Closed Bug 1831392 Opened 1 year ago Closed 1 year ago

Add an excluded credential prompt

Categories

(Core :: DOM: Web Authentication, enhancement, P3)

Firefox 114
enhancement

Tracking

()

VERIFIED FIXED
115 Branch
Tracking Status
firefox114 --- wontfix
firefox115 --- verified

People

(Reporter: jschanck, Assigned: jschanck)

References

(Blocks 2 open bugs)

Details

Attachments

(1 file)

An authenticator will return CTAP2_ERR_CREDENTIAL_EXCLUDED when it finds that it stores a valid credential that is listed in the authenticatorMakeCredential command's excludeList argument. This prevents the user from registering multiple credentials for the account on one authenticator.

We should show a prompt that guides the user towards retrying with a different authenticator when this happens.

Severity: -- → S3
Summary: Add a excluded credential prompt → Add an excluded credential prompt
Depends on: 1828926
Depends on: 1833240
Blocks: 1830848
Type: defect → enhancement
Pushed by jschanck@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/a21e2a30012a
add an excluded WebAuthn credential prompt. r=keeler
Status: NEW → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Target Milestone: --- → 115 Branch

Verified using the latest Nightly build 115.0a1 that user is now prompted with a notification message letting the user know that that device was already registered and to try a new device.

Testing was done using the following:

  • Yubico 5 NFC
  • Yubico Bio
  • Feitian ePass FIDO2 Security Key A4B
  • Windows 7, Ubuntu 20.04 and macOS 13
Blocks: 1828926
No longer depends on: 1828926

Does this need a Beta approval request?

Flags: needinfo?(jschanck)

I'll mark this as wontfix for 114. The existing patch doesn't apply cleanly, and I don't think it's a significant enough bug to warrant investing more time in it.

Flags: needinfo?(jschanck)
Status: RESOLVED → VERIFIED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: