Avoid registering the same authenticator twice

This passes existing credentials in the server response, to allow
the browser to prevent re-registering the same key for the same
user. Registering the same key multiple times doesn't seem to be
an issue technically; the user has likely got their keys mixed up.

- Chrome says "you don't need to register it again".
- Safari exits with an InvalidStateError.
- Firefox exits with a DOMException.
This commit is contained in:
Ben Thorner
2021-05-11 14:22:41 +01:00
parent e2cf3e2c70
commit 957dba4356
5 changed files with 27 additions and 9 deletions

View File

@@ -192,12 +192,9 @@ class UserApiClient(NotifyAdminAPIClient):
return self.get(endpoint)
def get_webauthn_credentials_for_user(self, user_id):
from datetime import datetime
return [{
'name': 'Ben test',
'created_at': datetime.now().strftime("%Y-%m-%dT%H:%M:%S.%fZ")
}]
# TODO: remove when using real API
self.credentials = getattr(self, 'credentials', [])
return self.credentials
def create_webauthn_credential_for_user(self, user_id, credential):
self.credentials = getattr(self, 'credentials', [])