diff --git a/classquiz/routers/login.py b/classquiz/routers/login.py index 52cad4a..b8432db 100644 --- a/classquiz/routers/login.py +++ b/classquiz/routers/login.py @@ -85,7 +85,7 @@ def verify_webauthn(data, fidocredentialss: list[FidoCredentials], login_session verify_authentication_response( credential=credential, expected_challenge=base64.b64decode(login_session.webauthn_challenge), - expected_rp_id=urllib.parse.urlparse(settings.root_address).netloc, + expected_rp_id=urllib.parse.urlparse(settings.root_address).hostname, expected_origin=settings.root_address, credential_public_key=user_cred.public_key, credential_current_sign_count=user_cred.sign_count, @@ -116,7 +116,7 @@ async def start_login(data: StartLoginInput): else: step_1.add(StartLoginResponseTypes.PASSKEY) webauthn_data = generate_authentication_options( - rp_id=urllib.parse.urlparse(settings.root_address).netloc, + rp_id=urllib.parse.urlparse(settings.root_address).hostname, allow_credentials=[ PublicKeyCredentialDescriptor(id=cred.id, type="public-key") for cred in user.fidocredentialss ], diff --git a/classquiz/routers/users/webauthn.py b/classquiz/routers/users/webauthn.py index 6750506..5aae386 100644 --- a/classquiz/routers/users/webauthn.py +++ b/classquiz/routers/users/webauthn.py @@ -28,7 +28,7 @@ router = APIRouter() async def request_add_key_data(user: User = Depends(get_current_user)): user = await User.objects.select_related("fidocredentialss").get(id=user.id) options = generate_registration_options( - rp_id=urllib.parse.urlparse(settings.root_address).netloc, + rp_id=urllib.parse.urlparse(settings.root_address).hostname, rp_name="ClassQuiz", user_id=user.id.hex, user_name=user.email, @@ -59,7 +59,7 @@ async def confirm_add_key_data(credential: RegistrationCredential, user: User = verification = verify_registration_response( credential=credential, expected_challenge=current_registration_challenge, - expected_rp_id=urllib.parse.urlparse(settings.root_address).netloc, + expected_rp_id=urllib.parse.urlparse(settings.root_address).hostname, expected_origin=settings.root_address, ) new_credential = FidoCredentials( diff --git a/frontend/src/routes/account/settings/security/+page.svelte b/frontend/src/routes/account/settings/security/+page.svelte index 9df95c8..12a9cfe 100644 --- a/frontend/src/routes/account/settings/security/+page.svelte +++ b/frontend/src/routes/account/settings/security/+page.svelte @@ -84,6 +84,9 @@ }; const get_backup_code = async () => { + if (!confirm('If you continue, your old backup-code will be removed.')) { + return; + } const res = await fetch('/api/v1/users/2fa/backup_code'); backup_code = (await res.json()).code; }; @@ -126,7 +129,7 @@ class="pointer-events-none inline-block h-4 w-4 translate-x-3 rounded-full bg-white transition will-change-transform" /> - Two Factor authentication is activated @@ -147,7 +150,7 @@ class="pointer-events-none inline-block h-4 w-4 translate-x-0 rounded-full bg-white transition will-change-transform" /> - Two Factor authentication is deactivated @@ -167,7 +170,11 @@ {/if}
- +