Repository navigation
Conversation
Updates `@simplewebauthn/browser` and `@simplewebauthn/server` dependencies to v13.2.2. This upgrade brings improved security and compatibility by aligning with the latest version of the library, addressing potential vulnerabilities and ensuring better integration with modern browser environments. It also changes the way options are passed to `startAuthentication` and `startRegistration` methods. The userID for registration options is now expected to be a Uint8Array. The authenticator's credential ID is no longer base64 encoded.
Updates the WebAuthn verification process to align with changes in the underlying SimpleWebAuthn library. This change streamlines the extraction and usage of credential information, resulting in a cleaner and more maintainable codebase. It simplifies the verification logic by directly passing credential data.
Updates the WebAuthn and Passkey provider documentation to reflect the SimpleWebAuthn v13 API changes. This includes clarifying the required peer dependencies, detailing the differences in the API (credential IDs as base64 strings, `verifyAuthenticationResponse` requiring a `credential` object, and the options shape for browser helpers), and updating the setup instructions accordingly. This ensures developers using these providers with SimpleWebAuthn v13 have accurate and up-to-date information.
Updates the `@simplewebauthn/browser` and `@simplewebauthn/server` peer dependencies to version 13.2.2 in the WebAuthn and Passkey documentation. Clarifies the usage of `@simplewebauthn/browser` dependency, emphasizing that it's only required for custom sign-in pages. Also, mentions that types are now exported from browser and server packages.
…impleWebAuthn v13/v14 upgrade
Builds on the previous commits (SimpleWebAuthn v9 -> v13 API migration) and
fixes what they left incomplete:
- Credential ID encoding. Auth.js stores credential IDs as standard base64
(`Buffer#toString("base64")`, including "+", "/" and "=") and normalises the
browser's ID to that format before `adapter.getAuthenticator()`. SimpleWebAuthn
v13+ exchanges IDs as base64url. Storing `credential.id` verbatim put new rows
in a different format from the lookup, so a newly registered passkey could
never sign in ("WebAuthn authenticator not found in database"). IDs now stay
standard base64 in the database, and are converted to base64url only at the
SimpleWebAuthn boundary (allowCredentials, excludeCredentials,
verifyAuthenticationResponse). Existing Authenticator rows need no migration.
- next-auth and @auth/sveltekit: the client helpers now call
startAuthentication/startRegistration with `{ optionsJSON }` (v11+ API; the
positional form only works through a deprecation shim that logs a warning).
- Peer ranges in @auth/core, next-auth and @auth/sveltekit:
`@simplewebauthn/server` ^13.3.2 || ^14.0.2 and `@simplewebauthn/browser`
^13.3.0 || ^14.0.0. The server floors carry GHSA-6hxq-p678-4hr2 (fixed in
13.3.2) and GHSA-2g3p-m8c9-hhwh (fixed in 14.0.2; v14 requires Node 22+, so
v13.3 stays allowed for Node 20). next-auth and @auth/sveltekit still
declared ^9, which made `npm install` fail with ERESOLVE next to v13.
- Default sign-in page browser script: v13.3.0. devDependencies: v14. The
nextjs example: @simplewebauthn/server ^14.0.2.
- Tests: fixture credential IDs now contain "+", "/" and "=" (hex IDs were
identical in base64 and base64url, which is why the encoding bug passed), the
browser response carries base64url as real browsers do, and two tests cover
the conversion helpers.
Co-authored-by: Rastislav <rastislav@onion.email>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ged credential storage Install instructions now point at the patched releases, note the Node 22 requirement of v14 (v13.3 for Node 20), and state that existing Authenticator records keep working without a data migration. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
@rvdlaar is attempting to deploy a commit to the authjs Team on Vercel. A member of the Team first needs to authorize it. |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
☕️ Reasoning
Moves WebAuthn/Passkey support from SimpleWebAuthn v9 to v13.3+ / v14. This clears two public SimpleWebAuthn advisories that Dependabot reports for every Auth.js app using passkeys:
x5cnot chained to a trust anchor. Fixed in 13.3.2.Both advisories are already published by SimpleWebAuthn, so nothing new is disclosed here. The PR builds on @rastislavcore's #13378, whose four commits are kept with their authorship, and completes it:
getAuthenticator(). SimpleWebAuthn v13+ uses base64url, and Update/passkey 01 #13378 storedcredential.idas-is, so a passkey registered after the upgrade could never sign in. This PR keeps the stored format and converts only at the SimpleWebAuthn boundary. No adapter or data migration is needed.next-authand@auth/sveltekitget their peer ranges updated (Update/passkey 01 #13378 left them at^9, which failsnpm installwithERESOLVE) and their client helpers moved to the{ optionsJSON }call form.v13.3.0, the docs cover v13.3+/v14, and the nextjs example uses^14.0.2.Review guide
packages/core/src/lib/utils/webauthn-utils.ts. Two small helpers (base64ToBase64URL,base64URLToBase64) are used at five call sites; the rest of the migration comes from Update/passkey 01 #13378.packages/next-auth/src/webauthn.tsandpackages/frameworks-sveltekit/src/lib/webauthn.ts, a one-line change each.pnpm-lock.yaml: only SimpleWebAuthn's own dependency tree changes.@peculiar/*ASN.1/X.509 packages andtsyringeare added;asn1js,cross-fetchand@simplewebauthn/typesare removed. Nothing else is re-resolved. The Socket report on this PR shows improved scores for both packages and no alerts.Impact for users (release-note draft)
@simplewebauthn/server@^14.0.2and@simplewebauthn/browser@^14.0.0(Node 22+). On Node 20, use@^13.3.2/@^13.3.0. Both ranges are allowed.Authenticatorrecords keep working; no database change is needed.registrationOptions,authenticationOptions,verifyRegistrationOptionsorverifyAuthenticationOptions. The one narrowing:attestationTypeno longer accepts"indirect"(SimpleWebAuthn v13.0.0 dropped it).@simplewebauthn/browserdirectly should usestartRegistration({ optionsJSON })/startAuthentication({ optionsJSON }). The old positional form still works but logs a deprecation warning.WebAuthn is behind
experimental.enableWebAuthn, so I believe afix:release is appropriate. I'm happy to change it tofeat:if you prefer.🧢 Checklist
Unit tests (
@auth/core): 162/162. The fixture credential IDs were hex, which reads the same in base64 and base64url, and that is why #13378's encoding bug passed. They now contain+,/and=, the browser response uses base64url, and two tests cover the helpers.@auth/core,next-authand@auth/sveltekitbuild (svelte-checkreports 0 errors), and their tests pass. The devDependencies use v14, so the repo itself has no open advisory. The floor of the range (@simplewebauthn/server@13.3.3,@simplewebauthn/browser@13.3.0) also builds and passes the same tests.prettier --checkandeslintreport 0 errors on the changed files.Real WebAuthn ceremonies (Chromium virtual authenticator, CTAP2 resident key) against a Next.js 16 app using
next-auth@5+Passkey+ a custom adapter. Packed builds of this branch were compared with the released packages:@auth/core0.41.3 + SimpleWebAuthn 9: register → sign in (control)WebAuthn authenticator not found in databaseSuggested squash commit message
🎫 Affected issues
Supersedes #13378 (its commits are included). Happy to close this in favour of that PR if the author prefers to pick up these changes there.
📌 Resources
🤖 Generated with Claude Code