iya-sts
    Preparing search index...

    Function verifyRegistration

    • Verifies a registration ceremony (WebAuthn section 7.1), apart from the attestation statement.

      Checks the client data type, challenge and origin, the RP ID hash, user presence (and verification when required), the attested credential data, the backup flags, the offered algorithms and the credential id's length. The attestation statement is returned for authn/webauthn_attestation.ts to verify.

      Parameters

      • input: any

        attestationObject and clientDataJSON (base64url), expectedChallenge, expectedOrigin, expectedRpId, and optionally requireUserVerification and expectedAlgorithms

      Returns {
          aaguid: any;
          algorithm: any;
          attStmt: any;
          authDataRaw: any;
          checks: any[];
          clientDataHash: any;
          coseAlg: any;
          credentialId: any;
          credentialIdRaw: any;
          credentialPublicKeyCose: any;
          failed: any[];
          flags: {
              at: boolean;
              be: boolean;
              bs: boolean;
              ed: boolean;
              up: boolean;
              uv: boolean;
          };
          fmt: any;
          ok: boolean;
          publicKeyJwk: | {
              crv: any;
              e?: undefined;
              kty: string;
              n?: undefined;
              pub?: undefined;
              x: any;
              y: any;
          }
          | {
              crv?: undefined;
              e: any;
              kty: string;
              n: any;
              pub?: undefined;
              x?: undefined;
              y?: undefined;
          }
          | {
              crv: any;
              e?: undefined;
              kty: string;
              n?: undefined;
              pub?: undefined;
              x: any;
              y?: undefined;
          }
          | {
              crv?: undefined;
              e?: undefined;
              kty: string;
              n?: undefined;
              pub: any;
              x?: undefined;
              y?: undefined;
          };
          rpIdHash: any;
          signCount: any;
      }

      ok, every check with its result, the credential id, public key JWK, algorithm, signature counter, flags and the attestation inputs

      when the attestation object or authenticator data cannot be decoded