feat(passkey-crypto): add derivePasskeyPrfKey function#8679
Open
feat(passkey-crypto): add derivePasskeyPrfKey function#8679
Conversation
043577b to
adc92b6
Compare
adc92b6 to
2db8709
Compare
Contributor
Author
|
@claude review this PR |
2db8709 to
2d56dae
Compare
e247cb7 to
d1e85f3
Compare
mohammadalfaiyazbitgo
requested changes
May 5, 2026
Comment on lines
+43
to
+49
| const result = await provider.get({ | ||
| publicKey: { | ||
| challenge: new Uint8Array(), | ||
| allowCredentials, | ||
| } as PublicKeyCredentialRequestOptions, | ||
| evalByCredential, | ||
| }); |
Contributor
There was a problem hiding this comment.
shouldn't we use the navigator object here?
Contributor
Author
There was a problem hiding this comment.
To keep things enviroment agnostic I dont think we can
Contributor
Author
There was a problem hiding this comment.
Updated — bitgo is now used to fetch a server-issued assertion challenge from /user/otp/webauthn/assertion, and the manual allowCredentials construction has been removed. The provider receives { publicKey: { challenge }, evalByCredential } and handles the navigator-level credential selection.
Buffer.from(challenge, 'base64') is consistent with the existing registerPasskey.ts pattern — Buffer extends Uint8Array and satisfies BufferSource, so no DOM compatibility issue there.
d1e85f3 to
2df086f
Compare
e345b43 to
e2c5ccd
Compare
- fetch keychain webauthn devices and build PRF eval map - fetch server-issued assertion challenge via bitgo - trigger WebAuthn assertion via provider (navigator layer) - derive hex wallet passphrase from PRF output Ticket: WCN-192
e2c5ccd to
09ca9e0
Compare
mohammadalfaiyazbitgo
approved these changes
May 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
https://linear.app/bitgo/issue/WCN-192/implement-derivepasskeyprfkey
Summary
derivePasskeyPrfKey()tomodules/sdk-core/src/bitgo/passkey/WebAuthnProvider, and returns hex-encoded wallet passphrasebuildEvalByCredential,matchDeviceByCredentialId,derivePasswordfrom@bitgo/passkey-crypto@bitgo/passkey-cryptoas a dependency insdk-core/package.jsonandtsconfig.jsonproject referenceTest plan
anytypes in implementationTicket: WCN-192