pub struct FinishWebAuthnAuthenticationRequest {
pub challenge_id: String,
pub credential_id: String,
pub client_data_json: Vec<u8>,
pub authenticator_data: Vec<u8>,
pub signature: Vec<u8>,
pub user_handle: Vec<u8>,
pub device_public_key: Vec<u8>,
pub client_operation_id: String,
pub biscuit_authority_public_key: Vec<u8>,
pub device_proof_public_key: Vec<u8>,
}Fields§
§challenge_id: StringThe server MUST resolve this pending ceremony, require credential_id to
be the credential selected for it, and verify the assertion challenge,
clientDataJSON.type == "webauthn.get", and expected origin. An assertion
from a different challenge_id ceremony MUST be rejected.
credential_id: String§client_data_json: Vec<u8>§authenticator_data: Vec<u8>§signature: Vec<u8>§user_handle: Vec<u8>§device_public_key: Vec<u8>Client-side device pubkey the client wants the access token bound to. Server validates this against the user’s active device_roots. Legacy one-key input only: after the GrantEnvelope v2 cutover a server MUST reject this as a substitute for either role-labelled key below and MUST NOT issue a v1 envelope from it.
client_operation_id: StringRaw 32-byte Ed25519 public key for the ephemeral Biscuit authority role.
Required together with device_proof_public_key; this key verifies the
client-minted authority block and never anchors request PoP.
device_proof_public_key: Vec<u8>Raw 32-byte Ed25519 public key for the non-extractable device-proof role.
Required together with biscuit_authority_public_key; the server validates
it against the user’s active device roots and places it in GrantEnvelope v2
as the initial delegated-PoP and Tier-1 request-signing anchor.
Trait Implementations§
Source§impl Clone for FinishWebAuthnAuthenticationRequest
impl Clone for FinishWebAuthnAuthenticationRequest
Source§fn clone(&self) -> FinishWebAuthnAuthenticationRequest
fn clone(&self) -> FinishWebAuthnAuthenticationRequest
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreimpl Eq for FinishWebAuthnAuthenticationRequest
Source§impl Message for FinishWebAuthnAuthenticationRequest
impl Message for FinishWebAuthnAuthenticationRequest
Source§fn encoded_len(&self) -> usize
fn encoded_len(&self) -> usize
Source§fn encode(&self, buf: &mut impl BufMut) -> Result<(), EncodeError>where
Self: Sized,
fn encode(&self, buf: &mut impl BufMut) -> Result<(), EncodeError>where
Self: Sized,
Source§fn encode_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
fn encode_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
Source§fn encode_length_delimited(
&self,
buf: &mut impl BufMut,
) -> Result<(), EncodeError>where
Self: Sized,
fn encode_length_delimited(
&self,
buf: &mut impl BufMut,
) -> Result<(), EncodeError>where
Self: Sized,
Source§fn encode_length_delimited_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
fn encode_length_delimited_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
Source§fn decode(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
fn decode(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
Source§fn decode_length_delimited(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
fn decode_length_delimited(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
Source§fn merge(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
fn merge(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
self. Read moreSource§fn merge_length_delimited(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
fn merge_length_delimited(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
self.