Skip to content

Instantly share code, notes, and snippets.

@ks75vl
Last active March 20, 2022 17:32
Show Gist options
  • Save ks75vl/f6c49785a28f361c342ee60a56c2be38 to your computer and use it in GitHub Desktop.
Save ks75vl/f6c49785a28f361c342ee60a56c2be38 to your computer and use it in GitHub Desktop.
WebAuthn Discoverable Credential (Resident Key)
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<!-- https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP -->
<meta http-equiv="Content-Security-Policy" content="default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'">
<title>Hello World!</title>
</head>
<body>
<h1>Hello World!</h1>
We are using Node.js <span id="node-version"></span>,
Chromium <span id="chrome-version"></span>,
and Electron <span id="electron-version"></span>.
<!-- You can also require other files to run in this process -->
<script src="./renderer.js"></script>
</body>
</html>
// Modules to control application life and create native browser window
const { app, BrowserWindow, protocol, session } = require('electron')
const path = require('path')
const url = require('url')
function createWindow() {
const partition = 'persist:example'
const ses = session.fromPartition(partition)
// Bypass WebAuthn restricted to secure contexts.
// More details: https://github.com/electron/electron/issues/24573#issuecomment-659341240
ses.protocol.interceptFileProtocol('http', (request, callback) => {
const { host, pathname } = url.parse(request.url);
if (host === 'localhost') {
callback({ path: path.normalize(`${__dirname}/${pathname}`) });
} else {
// all requests to http except localhost will be lost...
callback();
}
}, (error) => {
if (error) console.error('Failed to register protocol')
});
// Create the browser window.
const mainWindow = new BrowserWindow({
width: 800,
height: 600,
webPreferences: {
partition
}
})
// and load the index.html of the app.
mainWindow.loadURL('http://localhost/index.html')
// Open the DevTools.
mainWindow.webContents.openDevTools()
}
// This method will be called when Electron has finished
// initialization and is ready to create browser windows.
// Some APIs can only be used after this event occurs.
app.whenReady().then(() => {
createWindow()
app.on('activate', function () {
// On macOS it's common to re-create a window in the app when the
// dock icon is clicked and there are no other windows open.
if (BrowserWindow.getAllWindows().length === 0) createWindow()
})
})
// Quit when all windows are closed, except on macOS. There, it's common
// for applications and their menu bar to stay active until the user quits
// explicitly with Cmd + Q.
app.on('window-all-closed', function () {
if (process.platform !== 'darwin') app.quit()
})
// In this file you can include the rest of your app's specific main process
// code. You can also put them in separate files and require them here.
{
"name": "absorbing-signature-chop-m00aj",
"productName": "absorbing-signature-chop-m00aj",
"description": "My Electron application description",
"keywords": [],
"main": "./main.js",
"version": "1.0.0",
"author": "dtt",
"scripts": {
"start": "electron ."
},
"dependencies": {},
"devDependencies": {
"electron": "17.1.2"
}
}
window.onload = async () => {
// Create random challenge.
const challenge = new Uint8Array(32); crypto.getRandomValues(challenge);
console.log({ challenge });
// Get resident credential (by using `publicKey` without allowCredentials field).
// More details: https://www.w3.org/TR/webauthn-3/#discoverable-credential
try {
const cred = await navigator.credentials.get({
publicKey: {
rpId: 'localhost',
challenge,
userVerification: 'required'
}
});
console.log({ cred });
} catch (error) {
console.log({ error });
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment