Skip to content

Return public key metadata from user verification enrollment - #44877

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/f0726e8c430e27559e1a01ba2ea635993cbeba09
Sep 11, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/f0726e8c430e27559e1a01ba2ea635993cbeba09

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Return public key metadata from user verification enrollment

Why

The trusted UI host needs the local credential's public metadata to complete backend registration. userVerification/enroll previously returned only credentialId.

What changed

  • Return algorithm and publicKey for newly created or reused credentials. The algorithm is ecdsaP256Sha256X962; the public key is unpadded base64url SPKI-DER.
  • Keep both fields optional in the protocol for compatibility with older app-servers, while current servers populate both.
  • Document caller-owned backend registration and revocation, including checking metadata, signing an enrollment challenge with userVerification/verify, matching credential IDs, and preserving the authenticated account throughout registration.

Testing

Add protocol coverage for absent or null metadata and populated-response round trips. Add an RPC assertion for enrollment metadata and extend the local enrollment test to check metadata when creating and reusing a key.

## Why

The trusted UI host needs the local credential's public metadata to complete backend registration. `userVerification/enroll` previously returned only `credentialId`.

## What changed

- Return `algorithm` and `publicKey` for newly created or reused credentials. The algorithm is `ecdsaP256Sha256X962`; the public key is unpadded base64url SPKI-DER.
- Keep both fields optional in the protocol for compatibility with older app-servers, while current servers populate both.
- Document caller-owned backend registration and revocation, including checking metadata, signing an enrollment challenge with `userVerification/verify`, matching credential IDs, and preserving the authenticated account throughout registration.

## Testing

Add protocol coverage for absent or null metadata and populated-response round trips. Add an RPC assertion for enrollment metadata and extend the local enrollment test to check metadata when creating and reusing a key.

GitOrigin-RevId: f0726e8c430e27559e1a01ba2ea635993cbeba09
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/f0726e8c430e27559e1a01ba2ea635993cbeba09 branch from 48f0ce6 to 7b49128 Compare September 11, 2026 17:37
@copyberry
copyberry Bot merged commit 7b49128 into main Sep 11, 2026
@github-actions

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/f0726e8c430e27559e1a01ba2ea635993cbeba09 branch September 11, 2026 17:37
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 11, 2026

This branch was successfully deployed

1 active deployment
issue-triage — 7b491281 Deployed Sep 11, 2026 by lin08277-source via Translate non-English issue #12722
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants