Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Forcing another session to log out does not support WebAuthn #7696

Open
cendyne opened this issue Oct 9, 2023 · 1 comment
Open

Forcing another session to log out does not support WebAuthn #7696

cendyne opened this issue Oct 9, 2023 · 1 comment
Labels
A-Authentication O-Occasional Affects or can be seen by some users regularly or most users rarely S-Major Severely degrades major functionality or product features, with no satisfactory workaround T-Defect Something isn't working: bugs, crashes, hangs and other reported problems

Comments

@cendyne
Copy link

cendyne commented Oct 9, 2023

Steps to reproduce

Where are you starting? What can you see?

User Settings -> Security -> My Sessions -> Tap on a session -> Tap on "Sign out this session"

Then, by coincidence, it requires me to re-authenticate with my social identity provider, in this case GitHub.

GitHub then requires me to use my security key, because I use 2FA with GitHub.

I tap the use security key button in the web page.
It says "authentication failed", despite using it earlier to sign into this device.


Other notes:

I have experienced this with the Cisco AnyConnect app. We had to change our configuration so the iOS app uses a slightly different web view technology.

Something about how SFSafariWebView

Apple Documentation: ASWebAuthenticationSession

Yubico: No reaction when using WebAuthn on macOS, iOS and iPadOS

Apple: Meet Face ID and Touch ID for the Web

Element has no control on what or how the scripts run on a social login provider. This issue likely will only be resolved by switching the web view technology that comes up when tapping "Sign out this session".

Outcome

What did you expect?

I expect to be able to use my security key to authenticate with GitHub and then return to Element's UI to remove the session.

What happened instead?

I was blocked

Your phone model

iPhone 13 Pro Max

Operating system version

17.0.3

Application version

No response

Homeserver

No response

Will you send logs?

Yes

@cendyne cendyne added the T-Defect Something isn't working: bugs, crashes, hangs and other reported problems label Oct 9, 2023
@cendyne
Copy link
Author

cendyne commented Oct 9, 2023

Rage shaking was not recognized during this flow. I am unable to submit logs with that method. Here's a screenshot at least.

FD5AE240-F822-4794-92E5-5065D39A6AC2_1_101_o

Again, the issue is: The way Element iOS is creating this webview prevents successful use of WebAuthn security keys. This is not a case where my security key failed. I was never prompted to bring my security key to the device.

@Velin92 Velin92 added S-Major Severely degrades major functionality or product features, with no satisfactory workaround O-Occasional Affects or can be seen by some users regularly or most users rarely A-Authentication labels Oct 16, 2023
@github-project-automation github-project-automation bot moved this to Triaged in Issue triage Aug 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
A-Authentication O-Occasional Affects or can be seen by some users regularly or most users rarely S-Major Severely degrades major functionality or product features, with no satisfactory workaround T-Defect Something isn't working: bugs, crashes, hangs and other reported problems
Projects
Status: Triaged
Development

No branches or pull requests

2 participants