Version 2.6.0
webauthn-server-core:
New features:
- Added method
getParsedPublicKey(): java.security.PublicKeyto
RegistrationResultandRegisteredCredential.- Thanks to Jakob Heher (A-SIT) for the contribution, see #299
- Added enum parsing functions:
AuthenticatorAttachment.fromValue(String): Optional<AuthenticatorAttachment>PublicKeyCredentialType.fromId(String): Optional<PublicKeyCredentialType>ResidentKeyRequirement.fromValue(String): Optional<ResidentKeyRequirement>TokenBindingStatus.fromValue(String): Optional<TokenBindingStatus>UserVerificationRequirement.fromValue(String): Optional<UserVerificationRequirement>
- Added public builder to
CredentialPropertiesOutput. - Added public factory function
LargeBlobRegistrationOutput.supported(boolean). - Added public factory functions to
LargeBlobAuthenticationOutput. - Added
hintsproperty toStartRegistrationOptions,StartAssertionOptions,PublicKeyCredentialCreationOptionsandPublicKeyCredentialRequestOptions, and classPublicKeyCredentialHintto support them, to support thehintsparameter introduced in WebAuthn L3: https://www.w3.org/TR/2023/WD-webauthn-3-20230927/#dom-publickeycredentialcreationoptions-hints - (Experimental) Added option
isSecurePaymentConfirmation(boolean)toFinishAssertionOptions. When set,RelyingParty.finishAssertion()will adapt the validation logic for a Secure Payment Confirmation (SPC) response instead of an ordinary WebAuthn response. See the JavaDoc for details.- NOTE: Experimental features may receive breaking changes without a major version increase.
webauthn-server-attestation:
New features:
FidoMetadataDownloadernow parses the CRLDistributionPoints extension on the application level, so thecom.sun.security.enableCRLDP=truesystem property setting is no longer necessary.- Added helper function
CertificateUtil.parseFidoSernumExtensionfor parsing serial number from enterprise attestation certificates.
Artifacts built with openjdk version "17.0.13" 2024-10-15.