Conversation
Android の Credential Manager API における Restore Credentials のサーバー側 検証を行う新モジュール WebAuthnLite.Operation.RestoreCredential を追加する。 通常の Operation.Authenticate との主な違い: - UP/UV フラグを要求しないオプション(バックグラウンド実行対応) - BE (Backup Eligible) / BS (Backup State) フラグの検証オプションを追加 - origin に android:apk-key-hash:... 形式を使用 - clientDataJSON の type が設定可能(デフォルト "webauthn.get") Co-Authored-By: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
概要
Android の Credential Manager API における Restore Credentials のサーバー側検証を行う新モジュール
WebAuthnLite.Operation.RestoreCredentialを追加します。Google Play Store は 2027年4月 からサインイン機能を持つアプリに Restore Credentials 対応を必須化する予定です。
通常の
Operation.Authenticateとの違いclientDataJSON.typeデフォルト"webauthn.get""webauthn.get"(typeで上書き可能)origin形式https://...android:apk-key-hash:<Base64URL(SHA-256)>up_requiredup_required(false推奨)be_requiredオプションで追加可能bs_requiredオプションで追加可能新機能
validate_client_data_json/1typeオプションで期待する clientDataJSON の type を設定可能(デフォルト:"webauthn.get")validate_authenticator_assertion/1be_required: true— BE (Backup Eligible) フラグを必須に設定可能bs_required: true— BS (Backup State) フラグを必須に設定可能up_required: false)でも検証可能(バックグラウンド実行対応)使用例
実装上の注意点
credential_type = 'restore_key'などで管理を推奨。ユーザー向けパスキー管理 UI には非表示にすること00000000-0000-0000-0000-000000000000)になるため、AAGUID で識別可能テスト
validate_client_data_json— 5ケース(type / origin / challenge のバリデーション)validate_authenticator_assertion— 5ケース(BE/BS フラグ検証、署名エラー、RP ID エラーなど)参考
🤖 Generated with Claude Code