Skip to content

Drive auth settings from the API and enforce passkey server-side - #314

Closed
kaareal wants to merge 1 commit into
masterfrom
feature/passkey-auth-prompt-issue-b6a80e
Closed

kaareal wants to merge 1 commit into
masterfrom
feature/passkey-auth-prompt-issue-b6a80e

Conversation

@kaareal

@kaareal kaareal commented Sep 23, 2026

Copy link
Copy Markdown
Collaborator

What

  • AUTH_TYPE, AUTH_CHANNEL, AUTH_PASSKEY move from services/web/.env to services/api/.env (defaults: password, email, true).
  • GET /1/meta returns auth: { type, channel, passkey }.
  • /1/auth/passkey/* returns 403 when AUTH_PASSKEY is off.
  • Web session bootstrap always loads /1/meta first (also when logged out); a failure shows the error screen.
  • Login, Signup, the passkey button and the Settings passkey card read from meta.auth.
  • Removes unused OptionalPassword component.

Why

Passkey login was never offered because the web flag defaulted to empty, while Settings still let users register passkeys. The flag was also client-only: the API passkey routes were always live regardless of it. The API is now the single source of truth.

Reviewer notes

  • Staging/production env files layer over .env, so they inherit passkey on unless overridden.
  • OTP and signup routes still accept type/channel from the request body; the web now sends the API's configured values, but the API does not enforce them.
  • Web deploys no longer need AUTH_* vars; API deploys do if they differ from the defaults.

Testing

  • API route tests: 223 passed, including new passkey-disabled.test.js and updated meta.test.js.
  • Web build and lint pass. Not yet verified manually in the browser.

AUTH_TYPE, AUTH_CHANNEL and AUTH_PASSKEY move from the web env to the API
env and are exposed via /1/meta. The web loads meta before rendering (also
when logged out) and derives the login/signup forms and passkey UI from it.

Passkey was previously only a client-side toggle: the API routes were always
live. They now return 403 when AUTH_PASSKEY is off. The Settings passkey card
is hidden when passkey is disabled, so users can't register a passkey they
can't sign in with. Removes the unused OptionalPassword component.
@github-actions

Copy link
Copy Markdown

API Changes

No changes.

@andrewplummer

Copy link
Copy Markdown
Collaborator

there's an argument for API being single source of truth but there's also an argument for "API handles everything and what is enabled is a client side concern"

we defaulted to the former - it was a choice

@kaareal kaareal closed this Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants