Skip to content

feat: add a cache challenge store for API clients without a session - #152

Draft
RenzoMinelli wants to merge 2 commits into
rm--challenge-storefrom
rm--cache-challenge-store
Draft

RenzoMinelli wants to merge 2 commits into
rm--challenge-storefrom
rm--cache-challenge-store

Conversation

@RenzoMinelli

Copy link
Copy Markdown
Contributor

What: Adds ChallengeStores::Cache. It finds the challenge through the credential's clientDataJSON and consumes it once. Also accepts public_key_credential as a JSON object, respects skip_session_storage (:params_auth), and loads under an ActionController::API parent.

Why: This lets mobile clients without cookies sign in with passkeys. A React Native app on an iPhone signed in against a devise-jwt API with this stack.

How to test: bundle exec rspec spec/requests/devise/api_client_spec.rb spec/devise/webauthn/challenge_stores. The API specs start every request without cookies.

RenzoMinelli added a commit that referenced this pull request Sep 25, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@RenzoMinelli
RenzoMinelli marked this pull request as draft September 25, 2026 19:04
RenzoMinelli added a commit that referenced this pull request Sep 25, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@RenzoMinelli
RenzoMinelli force-pushed the rm--cache-challenge-store branch from 87acce5 to 05d846d Compare September 25, 2026 19:08
RenzoMinelli added a commit that referenced this pull request Sep 25, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@RenzoMinelli
RenzoMinelli force-pushed the rm--cache-challenge-store branch from 05d846d to ffe1a99 Compare September 25, 2026 19:25
@RenzoMinelli
RenzoMinelli force-pushed the rm--cache-challenge-store branch from ffe1a99 to 404ae7c Compare September 25, 2026 20:20
RenzoMinelli added a commit that referenced this pull request Sep 25, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
RenzoMinelli added a commit that referenced this pull request Sep 25, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@RenzoMinelli
RenzoMinelli force-pushed the rm--cache-challenge-store branch from 404ae7c to 9eb1ffd Compare September 25, 2026 20:34
@RenzoMinelli
RenzoMinelli added this pull request to stack #156 October 2, 2026 20:17
RenzoMinelli and others added 2 commits October 2, 2026 19:00
- `ChallengeStores::Cache` finds the challenge through the credential's
  clientDataJSON and consumes it once.
- Accept `public_key_credential` as a JSON object or string.
- Respect `skip_session_storage` (`:params_auth`) in both WebAuthn
  strategies.
- Load the options controllers under an `ActionController::API` parent.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@RenzoMinelli
RenzoMinelli force-pushed the rm--cache-challenge-store branch from 9eb1ffd to 6646a39 Compare October 2, 2026 22:06

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant