WebAuthn geavanceerd gebruiksvoorbeeld

· Componenten
WebAuthn geavanceerd gebruiksvoorbeeld

Hieronder vind je een uitgebreider Delphi-voorbeeld dat custom endpoints, challenge-beleid, database-gebaseerde credentialopslag, FIDO Metadata-validatie en cross-origin iframe-ondersteuning demonstreert. De code belicht geavanceerde event-afhandeling om beveiligingsbeleid af te dwingen. 

sgcWebSockets WebAuthn-server-voorbeeld

procedure TForm1.ConfigureWebAuthn;
begin
  // Component setup
  FWebAuthn := TsgcWSServer_API_WebAuthn.Create(nil);
  FWebAuthn.Server := FHTTPServer;
  FWebAuthn.Enabled := True;
  // Endpoint remapping
  FWebAuthn.EndpointsOptions.AuthenticationOptions.Endpoint := '/auth/options';
  FWebAuthn.EndpointsOptions.AuthenticationVerify.Endpoint  := '/auth/verify';
  FWebAuthn.EndpointsOptions.RegistrationOptions.Endpoint   := '/reg/options';
  FWebAuthn.EndpointsOptions.RegistrationVerify.Endpoint    := '/reg/verify';
  // Relying-party definition
  with FWebAuthn.WebAuthnOptions do
  begin
    RelyingParty := 'secure.example.com';
    Origins.Origins.Text      := 'https://app.example.com'#13#10'https://login.example.net';
    Origins.TopOrigins.Text   := 'https://host.example.org';
    Origins.AllowCrossOrigins := True;
    // Cryptographic & UX policies
    Algorithms                                   := [waunalgES256, waunalgRS256];
    DefaultOptions.Registration.UserVerification := waunuvPreferred;
    DefaultOptions.Registration.Attestation      := waunaDirect;
    Timeout                                      := 60000;
    // Challenge: 32 CSPRNG-random bytes, hex-encoded, generated internally by
    // the server; not configurable. Override Response.Challenge instead, in
    // OnWebAuthnRegistrationOptionsResponse / OnWebAuthnAuthenticationOptionsResponse.
    // Metadata Service configuration
    MDS.Enabled            := True;
    MDS.MDS_FileName       := 'mds.json';
    MDS.RootCert_FileName  := 'root.pem';
  end;
  // Hook events
  FWebAuthn.OnWebAuthnRegistrationOptionsRequest := AuthnRegOptionsRequest;
  FWebAuthn.OnWebAuthnRegistrationOptionsResponse := AuthnRegOptionsResponse;
  FWebAuthn.OnWebAuthnRegistrationValidateCertificate := AuthnRegVerify;
  FWebAuthn.OnWebAuthnRegistrationSuccessful     := AuthnRegSuccess;
  FWebAuthn.OnWebAuthnAuthenticationOptionsRequest := AuthnOptionsRequest;
  FWebAuthn.OnWebAuthnAuthenticationSuccessful     := AuthnSuccess;
end;

Event-implementaties

procedure TForm1.AuthnRegOptionsRequest(Sender: TObject;
  const Request: TsgcWebAuthn_RegistrationOptions_Request; var Accept: Boolean);
begin
  // Verify user is eligible for registration
  Accept := not UserExists(Request.Username);
end;
procedure TForm1.AuthnRegOptionsResponse(Sender: TObject;
  const Request: TsgcWebAuthn_RegistrationOptions_Request;
  const Response: TsgcWebAuthn_RegistrationOptions_Response);
begin
  // Optionally assign a user handle (binary identifier)
  Response.User.Id := HexToBin(UserGUIDToHex(GenerateGUID));
  Response.AuthenticatorSelection.AuthenticatorAttachment := 'platform';
end;
procedure TForm1.AuthnRegVerify(Sender: TObject;
  const Request: TsgcWebAuthn_RegistrationVerify_Request;
  const Validate: TsgcWebAuthnValidateAttestationStatement; var Accept: Boolean);
begin
  // Perform extra attestation validation against MDS entries
  Accept := ValidateAttestationWithMDS(Validate);
end;
procedure TForm1.AuthnRegSuccess(Sender: TObject;
  const Registration: TsgcWebAuthn_Registration;
  const CredentialRecord: TsgcWebAuthn_CredentialRecord; var Accept: Boolean);
begin
  // Persist credential details in database
  SaveCredentialToDB(
    CredentialRecord.Username,
    CredentialRecord.CredentialId,
    CredentialRecord.PublicKey,
    CredentialRecord.SignCount,
    CredentialRecord.UserId
  );
  Accept := True;
end;
procedure TForm1.AuthnOptionsRequest(Sender: TObject;
  const Request: TsgcWebAuthn_AuthenticationOptions_Request;
  var CredentialRecords: TsgcWebAuthn_CredentialRecords; var Accept: Boolean);
begin
  // Retrieve all credential records for user
  CredentialRecords := LoadCredentialRecordsFromDB(Request.Username);
  Accept := True;
end;
procedure TForm1.AuthnSuccess(Sender: TObject;
  const Request: TsgcWebAuthn_AuthenticationVerify_Request;
  const Authentication: TsgcWebAuthn_Authentication; var Accept: Boolean);
var
  StoredCounter: Cardinal;
begin
  // Ensure sign counter increases
  StoredCounter := GetSignCounterFromDB(Authentication.Credential.CredentialRecord.CredentialId);
  Accept := Authentication.Credential.CredentialRecord.SignCount > StoredCounter;
  if Accept then
  begin
    UpdateSignCounterInDB(Authentication.Credential.CredentialRecord.CredentialId,
      Authentication.Credential.CredentialRecord.SignCount);
    IssueSessionToken(Authentication.Credential.CredentialRecord.Username);
  end;
end;

Belangrijkste highlights

  1. Challenge-willekeurigheid – elke challenge wordt intern door de server gegenereerd als 32 cryptografisch willekeurige bytes, hexadecimaal gecodeerd, wat replay-aanvallen al weerstaat zonder extra configuratie.
  2. Custom user handles – door een unieke binaire user-handle toe te wijzen, kan de authenticator een privacybewarende identifier opslaan onafhankelijk van gebruikersnamen.
  3. Metadata-gebaseerde attestation-validatie – de routine ValidateAttestationWithMDS controleert het authenticator-model, statusrapporten en revocation-lijsten, en zorgt ervoor dat alleen vertrouwde apparaten worden geregistreerd.
  4. Sign-counter-handhaving – AuthnSuccess weigert reacties die de teller van de authenticator niet strikt verhogen, en detecteert zo gekloonde credentials.
  5. Database-integratie – credential-gegevens, sign-counters en sessietokens worden opgeslagen en bijgewerkt via externe persistentiefuncties, en laten zien hoe je het component integreert met een real-world backend.
  6. Cross-origin iframe-ondersteuning – ingeschakeld via AllowCrossOrigins en geconfigureerde TopOrigins, waardoor WebAuthn-flows gestart vanuit embedded frames mogelijk zijn (bv. een login-widget op een ander domein).
  7. Attestation-beleid – directe attestation gekoppeld aan MDS zorgt ervoor dat alleen goedgekeurde authenticators kunnen registreren, handig voor enterprise-compliance-scenario's.
  8. Transport-selectie – hoewel niet getoond, kunnen events de toegestane transports beperken (bv. USB,NFC,BLE) om aan te passen welke typen authenticators zijn toegestaan.