Skip to content

Harden Components/Account/Pages/Manage/Passkeys.razor #66865

@cincuranet

Description

@cincuranet

We should disable adding new passkey until the user has fully reauthenticated. Fair to say the security stamp validation by itself will prevent very stale cookies from working, but new cookies will not be invalidated, because the Identity system does not want to hit the DB every request.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area-identityIncludes: Identity and providers
    No fields configured for Feature.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions