From 9b307bacd17b41e16539cd5d88878c4855718e9a Mon Sep 17 00:00:00 2001 From: Bradley Schofield Date: Wed, 10 Jul 2024 20:03:36 +0900 Subject: [PATCH] Update webauthn deletion flow --- src/lib/sdk/account.ts | 42 +--- .../console/account/deleteWebauthn.svelte | 185 ------------------ src/routes/console/account/updateMfa.svelte | 24 ++- 3 files changed, 25 insertions(+), 226 deletions(-) delete mode 100644 src/routes/console/account/deleteWebauthn.svelte diff --git a/src/lib/sdk/account.ts b/src/lib/sdk/account.ts index 31cc73916..68f412b4e 100644 --- a/src/lib/sdk/account.ts +++ b/src/lib/sdk/account.ts @@ -121,44 +121,12 @@ export class Account { await this.completeMfaWebauthnChallenge(challenge.$id, credential); } - async deleteMfaWebauthnAuthenticator( - challengeId?: string, - credential?: Credential, - recoveryKey?: string - ) { - const path = '/account/mfa/authenticator/webauthn'; + async deleteMfaAuthenticator(type: string) { + const path = '/account/mfa/authenticators/' + type; const uri = new URL(this.client.config.endpoint + path); - - const body = {}; - - if (challengeId) { - body['challengeId'] = challengeId; - } - - if (credential) { - body['challengeResponse'] = JSON.stringify(credential); - } - - if (recoveryKey) { - body['recoveryKey'] = recoveryKey; - } - - return await this.client.call( - 'DELETE', - uri, - { - 'content-type': 'application/json' - }, - body - ); - } - - async deleteMfaWebauthnAuthenticatorHelper() { - const challenge = await this.createMfaWebauthnChallenge(); - - const credential = await startAuthentication(challenge); - - await this.deleteMfaWebauthnAuthenticator(challenge.$id, credential); + return await this.client.call('DELETE', uri, { + 'content-type': 'application/json' + }); } } diff --git a/src/routes/console/account/deleteWebauthn.svelte b/src/routes/console/account/deleteWebauthn.svelte deleted file mode 100644 index 75cf390be..000000000 --- a/src/routes/console/account/deleteWebauthn.svelte +++ /dev/null @@ -1,185 +0,0 @@ - - - - {#if step == 1} -

Please authenticate with your Webauthn Device to finish deletion.

-
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- {:else if step == 2} -

Enter your recovery code to finish deletion.

- - - - {/if} - - - - - {#if step == 1} - - - {:else if step == 2} - - - {/if} - -
diff --git a/src/routes/console/account/updateMfa.svelte b/src/routes/console/account/updateMfa.svelte index 2cf286c37..a4a1584df 100644 --- a/src/routes/console/account/updateMfa.svelte +++ b/src/routes/console/account/updateMfa.svelte @@ -15,7 +15,6 @@ import MfaRegenerateCodes from './mfaRegenerateCodes.svelte'; import { Pill } from '$lib/elements'; import WebauthnMfa from './webauthnMfa.svelte'; - import DeleteWebauthn from './deleteWebauthn.svelte'; let showSetup: boolean = false; let showDelete: boolean = false; @@ -78,6 +77,24 @@ } } + async function deleteWebauthnAuthenticator() { + try { + await sdk.forConsole.webauthnAccount.deleteMfaAuthenticator('webauthn'); + Promise.all([invalidate(Dependencies.ACCOUNT), invalidate(Dependencies.FACTORS)]); + trackEvent(Submit.AccountAuthenticatorDelete); + addNotification({ + type: 'success', + message: 'Webauthn authenticator has been deleted' + }); + } catch (error) { + addNotification({ + type: 'error', + message: error.message + }); + trackError(error, Submit.AccountAuthenticatorDelete); + } + } + $: if (!showRecoveryCodes) { codes = null; } @@ -162,12 +179,12 @@ + on:click={deleteWebauthnAuthenticator}>Delete + on:click={deleteWebauthnAuthenticator}>Delete {:else} @@ -269,7 +286,6 @@ {/if} -