Auth: Use plain browser guidance for passkeys #922

Open
opened 2026-10-02 17:40:11 +00:00 by kayg · 1 comment
Owner

Rule: the 2026-10-02 owner rule says not to name third-party products in the UI. Explain passkey support with plain words.

Findings:

  • apps/web/src/lib/auth/components/CreateAccountFlow.svelte:75 and apps/web/src/lib/auth/components/RecoverFlow.svelte:56: This browser can’t create passkeys here. Use a current Safari, Chrome, Edge or Firefox over a secure connection. Say This browser cannot create passkeys here. Use a recent browser with passkey support and a secure connection.
  • apps/web/src/lib/auth/passkeys.ts:186-191: the default passkey name can be Edge, Firefox, Chrome, or Safari (for example, Chrome on macOS). Use Browser on {platform} so a saved passkey name does not show a vendor name.

Expected: passkey help and the default passkey name explain the browser requirement without product names.

Test idea: check setup, invite, recovery and passkey naming with browser strings for each supported family. Confirm that all flows still create the same passkey and that the saved name is useful.

Rule: the 2026-10-02 owner rule says not to name third-party products in the UI. Explain passkey support with plain words. Findings: - `apps/web/src/lib/auth/components/CreateAccountFlow.svelte:75` and `apps/web/src/lib/auth/components/RecoverFlow.svelte:56`: `This browser can’t create passkeys here. Use a current Safari, Chrome, Edge or Firefox over a secure connection.` Say `This browser cannot create passkeys here. Use a recent browser with passkey support and a secure connection.` - `apps/web/src/lib/auth/passkeys.ts:186-191`: the default passkey name can be `Edge`, `Firefox`, `Chrome`, or `Safari` (for example, `Chrome on macOS`). Use `Browser on {platform}` so a saved passkey name does not show a vendor name. Expected: passkey help and the default passkey name explain the browser requirement without product names. Test idea: check setup, invite, recovery and passkey naming with browser strings for each supported family. Confirm that all flows still create the same passkey and that the saved name is useful.
Author
Owner

Line reference correction: the browser names in defaultPasskeyName are at apps/web/src/lib/auth/passkeys.ts:187-191; line 200 combines that name with the platform. Use apps/web/src/lib/auth/passkeys.ts:187-200 for this finding.

Line reference correction: the browser names in `defaultPasskeyName` are at `apps/web/src/lib/auth/passkeys.ts:187-191`; line 200 combines that name with the platform. Use `apps/web/src/lib/auth/passkeys.ts:187-200` for this finding.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#922
No description provided.