โ MPO WebAuthn Authentication Server
A production-ready WebAuthn (FIDO2/Passkeys) authentication server built with KTor and comprehensive security testing.
โ ๐๏ธ Multi-Module Project Structure
This project follows a multi-module architecture for clear separation of concerns:
webauthn-server/ - Main WebAuthn KTor server with production features
webauthn-test-credentials-service/ - HTTP service for cross-platform testing credentials
webauthn-test-lib/ - Shared WebAuthn test utilities library
android-test-client/ - Android client with generated API library
test-client/ - Web-based Playwright E2E tests
โ ๐ Quick Start
โ Prerequisites
Java 21+
Docker & Docker Compose
Node.js 18+ (for web tests)
โ Running the Server
# Start with Docker (recommended)
cd webauthn-server
./start-dev.sh
# Or run directly (requires local Redis/PostgreSQL)
./gradlew :webauthn-server:run
Copy
โ Running Tests
# Server tests
./gradlew :webauthn-server:test
# Android client tests
cd android-test-client && ./gradlew test
# Web E2E tests (requires server running)
cd test-client
npm install
npm test
Copy
โ ๐ Port Assignments
WebAuthn Server : 8080 (main API)
WebAuthn Test Service : 8081 (cross-platform credential generation)
Test Client : 8082 (E2E test web frontend)
PostgreSQL : 5432
Redis : 6379
Jaeger UI : 16686
โ ๐ Security Features
WebAuthn 2.0/FIDO2 compliance using Yubico library
Username enumeration protection - Authentication start doesn't reveal user existence
Replay attack prevention - Challenge/response validation
Cross-origin protection - Proper RP ID validation
Comprehensive vulnerability testing - 7 security test categories
โ ๐ฑ Client Generation
Generate client libraries for multiple platforms:
# Generate Android client
./gradlew :webauthn-server:copyGeneratedClientToLibrary
# Generate all clients (when implemented)
./gradlew :webauthn-server:generateAllClients
Copy
โ ๐งช Testing Architecture
The project uses a layered testing approach with different access patterns:
โ Testing Layers
webauthn-test-lib - Shared credential generation library
webauthn-test-credentials-service - HTTP API wrapper (port 8081)
Integration tests - Use shared library directly for performance
โ Cross-Platform Testing
Start the test service for external clients:
# Start test service
./gradlew :webauthn-test-credentials-service:run
# Test endpoints available at http://localhost:8081
# - POST /test/generate-registration-credential
# - POST /test/generate-authentication-credential
# - POST /test/clear
# - GET /test/sessions
Copy
Architecture Decisions :
webauthn-server integration tests : Use shared library directly for performance and reliability
Android client tests : Use HTTP API calls to webauthn-test-credentials-service for realistic cross-platform testing
โ ๐ Monitoring & Observability
OpenTelemetry tracing with OTLP export
Micrometer metrics with Prometheus export
Automated vulnerability monitoring - Weekly scans with PR generation
Code coverage reports with Kover
โ ๐๏ธ Architecture
โ Storage
PostgreSQL - Credential storage with quantum-safe encryption
Redis - Session and challenge storage
HikariCP - Connection pooling
Flyway - Database migrations
โ Security
Post-quantum cryptography preparation with BouncyCastle
Koin dependency injection for testability
CBOR encoding for WebAuthn data structures
OpenAPI 3.0 specification with Swagger UI
Jackson JSON processing with Kotlin support
CORS configuration for web clients
โ ๐ Documentation
โ ๐ ๏ธ Development
โ Module Commands
# Main server
./gradlew :webauthn-server:test
./gradlew :webauthn-server:run
./gradlew :webauthn-server:koverHtmlReport
# Test service
./gradlew :webauthn-test-credentials-service:build
./gradlew :webauthn-test-credentials-service:run
# Shared test library
./gradlew :webauthn-test-lib:build
# Android client
cd android-test-client && ./gradlew test
cd android-test-client && ./gradlew client-library:publish
Copy
โ Docker Development
# Start all dependencies
cd webauthn-server
./start-dev.sh
# View logs
docker-compose logs -f
# Stop services
docker-compose down
Copy
โ ๐ค Contributing
Follow security-first development practices
All WebAuthn changes require security test coverage
Use git mv for file moves to preserve history
Generate clients after API changes
Update documentation for structural changes
โ ๐ License
[Add your license here]