Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
  • Register
  • Sign in
  • G gitlab-ce
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Issues 0
    • Issues 0
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 1
    • Merge requests 1
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Monitor
    • Monitor
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • nexedinexedi
  • gitlab-ce
  • Repository
  • gitlab-ce
  • spec
  • javascripts
  • u2f
  • authenticate_spec.coffee
Find file BlameHistoryPermalink
  • Timothy Andrew's avatar
    Use a single challenge for U2F authentication. · 3572582d
    Timothy Andrew authored Jul 11, 2016
    1. According to the spec, either we have a single challenge with
       a number of `signRequests`, or a number of `signRequests`, each with
       it's own challenge.
    
    2. Previously, we had both these - per-request challenges, as well as a
       single extra challenge.
    
    3. This commit changes this so that the per-request challenges are
       removed, leaving only a single challenge, as per the v1.1 U2F API.
    
    4. The existing implementation didn't work in Firefox, because the
       Firefox (extension) implementation is less flexible with regard to
       the inputs.
    
    5. Fix teaspoon specs.
    
    6. References: https://fidoalliance.org/specs/fido-u2f-v1.0-nfc-bt-amendment-20150514/fido-u2f-javascript-api.html#h2_background
    3572582d
GitLab Nexedi Edition | About GitLab | About Nexedi | 沪ICP备2021021310号-2 | 沪ICP备2021021310号-7