Repository navigation
Let YubiKeys be added by tapping them, checked with YubiCloud - #174
Merged
Merged
Conversation
A factory YubiKey's OTP secret is known only to Yubico, so the server can't check its OTPs itself. That's why adding a YubiKey needed a slot reprogrammed with ykman. With a Yubico client ID and API key configured (COCOON_YUBICO_CLIENT_ID / COCOON_YUBICO_API_KEY), adding one is now: tap the key into a box on /account/2fa. Signing in is the same tap, in the Bluesky app's code box or on the signin page used by OAuth. - internal/yubicloud: a client for Yubico's validation protocol v2.0. It signs requests. It trusts a reply that decides the result (OK, BAD_OTP, REPLAYED_*) only if the reply is signed and echoes this request's otp and nonce. BAD_OTP replies, which Yubico sends without the echoes, must instead carry a current signed timestamp. - The key's public ID ties an OTP to an account. OTPs from other keys are rejected without being sent to Yubico. - If Yubico can't be reached, or the settings are later removed, sign-in reports that the YubiKey couldn't be checked, without counting it as a wrong code. - Without the settings, the existing ykman setup still works, and keys already added that way are unaffected. Setting only one of the two settings, or a malformed API key, stops startup.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ykman. With a Yubico API key configured, you tap the key into a box on/account/2fa, and sign in by tapping it into the Bluesky app's code box or the OAuth signin page.ykmansetup still works, and keys already added that way are unaffected.Changes
internal/yubicloudpackage: a client for Yubico's validation protocol v2.0.OK,REPLAYED_OTPandREPLAYED_REQUESTmust also echo this request'sotpandnonce.BAD_OTPwithout those echoes, so an echo-lessBAD_OTPmust instead carry a signed timestamp within 5 minutes.internal/yubicloud/yubicloudtest: a fake YubiCloud server for tests. It checks request signatures and nonces, rejects repeated OTPs, signs replies, and has switches for tampered or failing replies.COCOON_YUBICO_CLIENT_ID/COCOON_YUBICO_API_KEY(--yubico-client-id/--yubico-api-key), added to the Docker Compose files and the README. Setting only one of them, or a malformed API key, stops startup rather than silently turning the feature off./account/2fa/yubikeyasks only for a name, the password (plus a current code if 2FA is already on), and a tap. The YubiKey box comes last, because the key presses Enter and submits the form.Secretempty;TwoFactorCredential.UsesYubiCloud()). Adding the same key to one account twice is refused.createSessionreturns 503YubiKeyCheckUnavailablewith an explanation, and the signin page shows a message.Validation
CGO_ENABLED=1 go test -race ./...: all packages pass.go vet ./...andgofmt -l .are clean.BAD_OTPwith and without echoes, and signed-timestamp handling (including Yubico's documented example value2008-11-21T06:11:55Z0711). Plus 18 cases of untrustworthy replies, all of which must produce an error rather than a valid OTP: bad or missing signature, wrong otp or nonce echo, forged or unsigned rejections, a stale echo-lessBAD_OTP, HTTP 500, error statuses, an unknown status, a wrong API key, and a timeout.ykmanflow when Yubico isn't configured, and the settings validationBAD_OTPcould be played back (pass 3; reported twice, rated low by the verifying model)api.yubico.comwith a real YubiKey (no Yubico API key or hardware here). The signing follows the spec and matches Yubico's reference server (yubikey-val) and theyubigoGo client, but a live check before relying on this is worthwhile.Review notes
api.yubico.comis down, YubiKey sign-in fails until it's back. Authenticator codes and backup codes still work.ykmankeep being checked locally, even when Yubico is configured.