Class PublicKeyCredentialCreationOptions

java.lang.Object
com.codename1.backend.security.webauthn.PublicKeyCredentialCreationOptions

public final class PublicKeyCredentialCreationOptions extends Object

What a client is given to make a passkey with: the relying party, the user, a challenge, and what kind of credential is wanted.

toMap() is the WebAuthn JSON form, PublicKeyCredentialCreationOptionsJSON -- byte strings in base64url without padding -- which is what a browser's PublicKeyCredential.parseCreationOptionsFromJSON and the Codename One client's PublicKeyCredentialCreationOptions.fromJson take as it is:

{"rp": {"id": "example.com", "name": "Example"},
 "user": {"id": "q83v...", "name": "ada", "displayName": "ada"},
 "challenge": "9zV1...",
 "pubKeyCredParams": [{"type": "public-key", "alg": -7},
                      {"type": "public-key", "alg": -257}],
 "timeout": 300000,
 "excludeCredentials": [{"type": "public-key", "id": "mF2k..."}],
 "authenticatorSelection": {"residentKey": "required", "requireResidentKey": true,
                            "userVerification": "preferred"},
 "attestation": "none",
 "extensions": {"credProps": true}}

Made by WebAuthnRelyingPartyOperations.createPublicKeyCredentialCreationOptions(String).

  • Method Details

    • getRp

    • getUser

    • getChallenge

      public byte[] getChallenge()
      The challenge the authenticator's answer must carry back.
    • getTimeout

      public long getTimeout()
      How long the client may take, in milliseconds: a hint to it.
    • getUserVerification

      public String getUserVerification()
      required, preferred or discouraged.
    • getResidentKey

      public String getResidentKey()
      required, preferred or discouraged: whether the credential must be one a sign-in can find without being told the user.
    • getAuthenticatorAttachment

      public String getAuthenticatorAttachment()
      platform, cross-platform, or null for either.
    • getExcludeCredentials

      public List<byte[]> getExcludeCredentials()
      The ids of the credentials the user has already, which the authenticator holding one of them will not make another beside.
    • toMap

      public Map<String,Object> toMap()
      The options as the JSON a client takes; see the class.
    • fromMap

      public static PublicKeyCredentialCreationOptions fromMap(Map stored)
      The options toMap() wrote, read back from where a ceremony's pending state is kept; null when stored is not that.