docs: synced passkeys are allowed by default - #144
Open
Bccorb wants to merge 1 commit into
Open
Conversation
The auth API defaults authenticator_policy.syncedPasskeys to allow, so a stock deployment enrols iCloud Keychain and Google Password Manager passkeys rather than refusing them. synced_passkey_not_allowed is still reachable, since a deployment issuing its own authenticators sets block and the SDK cannot tell from the client which way the API is configured. The guidance to branch on the code rather than render the message is unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follows fells-code/seamless-auth-api#260 and fells-code/seamless-auth-types#61, which flip
authenticator_policy.syncedPasskeystoallow.The README and AGENTS.md both said the API defaults to
block, and drew the conclusion thatsynced_passkey_not_allowedis "the default path, not an edge case". Neither is true once that ships: a stock deployment now enrols the passkeys iCloud Keychain and Google Password Manager create.The refusal is still worth handling. A deployment issuing its own authenticators sets
block, and the SDK cannot tell from the client which way the API is configured, so the guidance to branch ongetPasskeyPolicyErrorCode()rather than render the message is unchanged. Only the framing moves, from "this is what you will hit by default" to "this is reachable and you cannot detect it in advance".Docs only. No SDK behaviour changes, so no changeset.
Checks
npm run typecheckcleannpm run lintcleannpm run format:checkcleannpm test319 passed (32 suites)