Server implementation for webauthn based on Yubico's java-webauthn-server
1.4K
A production-ready WebAuthn (FIDO2/Passkeys) authentication server built with KTor and comprehensive security testing.
This project follows a multi-module architecture for clear separation of concerns:
# Start with Docker (recommended)
cd webauthn-server
./start-dev.sh
# Or run directly (requires local Redis/PostgreSQL)
./gradlew :webauthn-server:run
# Server tests
./gradlew :webauthn-server:test
# Android client tests
cd android-test-client && ./gradlew test
# Web TypeScript client tests (requires server running)
cd web-test-client
npm install
npm run build # Build TypeScript client
npm test # Run Playwright E2E tests
Use the WebAuthn API in your applications with automatically published client libraries featuring enhanced regex validation and unified 3-part versioning:
dependencies {
implementation 'com.vmenon.mpo.api.authn:mpo-webauthn-android-client:1.0.26'
}
Enhanced Version Validation: All published versions use robust regex validation ensuring full npm semver compliance with support for advanced prerelease identifiers including hyphens.
npm install @vmenon25/mpo-webauthn-client
Generate client libraries locally for development:
# Generate Android client
./gradlew :webauthn-server:copyGeneratedClientToLibrary
# Generate TypeScript web client
./gradlew :webauthn-server:copyGeneratedTsClientToWebTestClient
# Generate all clients
./gradlew :webauthn-server:generateAllClients
The project uses a layered testing approach with different access patterns:
Start the test service for external clients:
# Start test service
./gradlew :webauthn-test-credentials-service:run
# Test endpoints available at http://localhost:8081
# - POST /test/generate-registration-credential
# - POST /test/generate-authentication-credential
# - POST /test/clear
# - GET /test/sessions
Architecture Decisions:
# Main server
./gradlew :webauthn-server:test
./gradlew :webauthn-server:run
./gradlew :webauthn-server:koverHtmlReport
# Test service
./gradlew :webauthn-test-credentials-service:build
./gradlew :webauthn-test-credentials-service:run
# Shared test library
./gradlew :webauthn-test-lib:build
# Android client
cd android-test-client && ./gradlew test
cd android-test-client && ./gradlew client-library:publish
# TypeScript web client
cd web-test-client && npm run build
cd web-test-client && npm test
# Start all dependencies
cd webauthn-server
./start-dev.sh
# View logs
docker-compose logs -f
# Stop services
docker-compose down
git mv for file moves to preserve historyThis project is licensed under the Apache License 2.0 - see the LICENSEโ file for details.
Copyright 2024 Vinayak Menon
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
Content type
Image
Digest
sha256:c66a13a31โฆ
Size
143 MB
Last updated
11 months ago
docker pull hitoshura25/webauthn-server