Passkeys: explain a full key set without a wait timer #945

Open
opened 2026-10-02 19:51:39 +00:00 by kayg · 0 comments
Owner

Follow-up from #734 review finding R2.

Evidence:

  • crates/calternal-auth/src/store.rs uses one insertion bound: 64 keys and 32 KiB of credential IDs plus UTF-8 key JSON. A full set returns AuthError::RateLimited, which gives HTTP 429.
  • apps/web/src/routes/settings/api.svelte.ts maps HTTP 429 to Too many attempts. Wait a minute, then try again.
  • This set limit does not expire. The User must remove a key to free capacity. The passkey_capacity regression checks refusal at the count and byte bounds. Existing keys can still verify and be removed.

Expected: when the saved key set is full, tell the User to remove a key before adding another. Keep the wait guidance for temporary ceremony limits. Use plain words.

This is a non-blocking error-text gap from #734. It does not allow an oversized key set or prevent verification and removal.

Test idea: fill a valid supported key set, try to add a key through Settings, and check the capacity message. Also check that a temporary ceremony limit keeps its retry guidance. Do not change authority checks or the insertion bounds.

Follow-up from #734 review finding R2. Evidence: - `crates/calternal-auth/src/store.rs` uses one insertion bound: 64 keys and 32 KiB of credential IDs plus UTF-8 key JSON. A full set returns `AuthError::RateLimited`, which gives HTTP 429. - `apps/web/src/routes/settings/api.svelte.ts` maps HTTP 429 to `Too many attempts. Wait a minute, then try again.` - This set limit does not expire. The User must remove a key to free capacity. The `passkey_capacity` regression checks refusal at the count and byte bounds. Existing keys can still verify and be removed. Expected: when the saved key set is full, tell the User to remove a key before adding another. Keep the wait guidance for temporary ceremony limits. Use plain words. This is a non-blocking error-text gap from #734. It does not allow an oversized key set or prevent verification and removal. Test idea: fill a valid supported key set, try to add a key through Settings, and check the capacity message. Also check that a temporary ceremony limit keeps its retry guidance. Do not change authority checks or the insertion bounds.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#945
No description provided.