Servidor WebAuthn para Delphi
Add passkey-based passwordless authentication to your Delphi server. WebAuthn Level 2 / FIDO2 registration and authentication ceremonies, attestation verification, credential storage hooks.
Add passkey-based passwordless authentication to your Delphi server. WebAuthn Level 2 / FIDO2 registration and authentication ceremonies, attestation verification, credential storage hooks.
Implements the WebAuthn relying-party server side — create credential challenges, verify navigator.credentials responses, parse attestation statements and validate assertion signatures.
TsgcWSAPIServer_WebAuthn
Windows, macOS, Linux, iOS, Android
Enterprise
Añade un TsgcWSAPIServer_WebAuthn sobre un TsgcWebSocketHTTPServer, define WebAuthnOptions.RelyingParty y gestiona OnWebAuthnRegistrationSuccessful para guardar cada passkey nueva y OnWebAuthnAuthenticationGetCredential para recuperarla al iniciar sesión.
uses
sgcWebSocket, sgcWebSocket_Server_APIs, sgcWebAuthn_Classes;
// Server: TsgcWebSocketHTTPServer and WebAuthn: TsgcWSAPIServer_WebAuthn are form fields
procedure TForm1.StartServer;
begin
Server := TsgcWebSocketHTTPServer.Create(nil);
Server.Port := 8443;
Server.SSL := True;
Server.SSLOptions.CertFile := 'server.pem';
Server.SSLOptions.KeyFile := 'server.pem';
Server.SSLOptions.Port := 8443;
WebAuthn := TsgcWSAPIServer_WebAuthn.Create(nil);
WebAuthn.Server := Server;
WebAuthn.WebAuthnOptions.RelyingParty := 'example.com';
WebAuthn.OnWebAuthnRegistrationSuccessful := OnRegistrationSuccessful;
WebAuthn.OnWebAuthnAuthenticationGetCredential := OnGetCredential;
Server.Active := True;
end;
procedure TForm1.OnRegistrationSuccessful(Sender: TObject;
const aRegistration: TsgcWebAuthn_Registration;
const aCredentialRecord: TsgcWebAuthn_CredentialRecord; var Accept: Boolean);
begin
// store the new passkey in your own database
SaveCredential(aCredentialRecord.CredentialId, aCredentialRecord.AsJSON);
end;
procedure TForm1.OnGetCredential(Sender: TObject; const aCredentialId: string;
const aCredentialRecord: TsgcWebAuthn_CredentialRecord; var Found: Boolean);
var
vJSON: string;
begin
// sign in: load the stored passkey back
vJSON := LoadCredential(aCredentialId);
Found := vJSON <> '';
if Found then
aCredentialRecord.ReadJSON(vJSON);
end;
// uses: sgcWebSocket, sgcWebSocket_Server_APIs
TsgcWebSocketHTTPServer *Server = new TsgcWebSocketHTTPServer(this);
TsgcWSAPIServer_WebAuthn *WebAuthn = new TsgcWSAPIServer_WebAuthn(this);
WebAuthn->Server = Server;
WebAuthn->WebAuthnOptions->RelyingParty = "example.com";
Server->Active = true;
A relying-party server that turns a Delphi process into a passkey-aware authentication endpoint.
OnWebAuthnRegistrationOptionsRequest accepts the request for PublicKeyCredentialCreationOptions; the browser invokes navigator.credentials.create(); the server validates the attestation and OnWebAuthnRegistrationSuccessful returns the new credential record.
OnWebAuthnAuthenticationOptionsRequest fills PublicKeyCredentialRequestOptions with the previously stored credential records; the server validates the assertion signature using the stored public key and fires OnWebAuthnAuthenticationSuccessful.
Supports none, packed, fido-u2f, tpm, android-key, android-safetynet and apple attestation statement formats.
Tracks the per-credential signCount to detect cloned authenticators. If the counter regresses, OnWebAuthnAuthenticationError reports an error you can act on.
UserVerification can be set to required, preferred or discouraged per ceremony — the validation step enforces the choice.
OnWebAuthnAuthenticationOptionsRequest hands you the request so you return the right CredentialRecords for the allowCredentials list of the in-progress login. Storage is yours to design.
Fuentes autorizadas de los estándares que implementa este componente.
Una passkey es una credencial WebAuthn detectable que guarda Windows Hello, iCloud Keychain, Google Password Manager o una llave de seguridad. El servidor admite la experiencia de passkey completa mientras las credenciales permanecen en tu propia base de datos.
Solicita las opciones de autenticación sin un nombre de usuario. El navegador muestra las passkeys que tiene para tu sitio, el usuario elige una y el servidor comprueba el userHandle devuelto.
Con mediación condicional, las passkeys aparecen en la lista de autocompletado del campo de nombre de usuario. Añade autocomplete="username webauthn" y llama a startAuthentication(options, true) desde /sgcWebAuthn.js.
Registra una passkey en el portátil y otra en el móvil. Todas las passkeys de una cuenta comparten un mismo user handle y las opciones de autenticación las incluyen todas.
BackupEligible y BackupState en el registro de credencial distinguen una passkey sincronizada de una llave de seguridad vinculada al dispositivo, así puedes sugerir una segunda passkey a los usuarios con un solo dispositivo.
Guarda el registro en OnWebAuthnRegistrationSuccessful, busca la credencial de un inicio de sesión sin nombre de usuario o por autocompletado en OnWebAuthnAuthenticationGetCredential, y guarda el nuevo contador en OnWebAuthnAuthenticationSuccessful.
Un contador de firma que no avanza se rechaza como posible clon, igual que un indicador de elegibilidad de copia de seguridad que cambia entre inicios de sesión. Las passkeys sincronizadas que siempre notifican 0 siguen funcionando.
Lee Passkeys en Delphi: inicio de sesión sin contraseña con WebAuthn y el tema de ayuda sobre Passkeys.
Enlace directo a la referencia del componente, descarga el proyecto demo listo para ejecutar y la prueba gratuita.
| Online Help — TsgcWSAPIServer_WebAuthn Referencia completa de propiedades, métodos y eventos de este componente. | Abrir | |
| Demo Project — Demos\20.HTTP_Protocol\12.WebAuthn Proyecto de ejemplo listo para ejecutar. Se incluye en el paquete sgcWebSockets — descarga la prueba gratuita más abajo. | Abrir | |
| Documento técnico (PDF) Características, inicio rápido, ejemplos de código para Delphi y C++ Builder y referencias de fuentes primarias — solo este componente. | Abrir | |
| Manual de usuario (PDF) Manual completo que cubre todos los componentes de la biblioteca. | Abrir |