|
| 1 | +/** |
| 2 | + * WebAuthn credential management (list, rename, delete) for the user profile page. |
| 3 | + */ |
| 4 | +import { getCsrfToken, getCsrfHeaderName, isWebAuthnSupported, escapeHtml } from '/js/user/webauthn-utils.js'; |
| 5 | +import { registerPasskey } from '/js/user/webauthn-register.js'; |
| 6 | +import { showMessage } from '/js/shared.js'; |
| 7 | + |
| 8 | +const csrfHeader = getCsrfHeaderName(); |
| 9 | +const csrfToken = getCsrfToken(); |
| 10 | + |
| 11 | +/** |
| 12 | + * Load and display user's passkeys. |
| 13 | + */ |
| 14 | +export async function loadPasskeys() { |
| 15 | + const container = document.getElementById('passkeys-list'); |
| 16 | + const globalMessage = document.getElementById('passkeyMessage'); |
| 17 | + if (!container) return; |
| 18 | + |
| 19 | + try { |
| 20 | + const response = await fetch('/user/webauthn/credentials', { |
| 21 | + headers: { [csrfHeader]: csrfToken } |
| 22 | + }); |
| 23 | + |
| 24 | + if (!response.ok) { |
| 25 | + throw new Error('Failed to load passkeys'); |
| 26 | + } |
| 27 | + |
| 28 | + const credentials = await response.json(); |
| 29 | + displayCredentials(container, credentials); |
| 30 | + } catch (error) { |
| 31 | + console.error('Failed to load passkeys:', error); |
| 32 | + if (globalMessage) { |
| 33 | + showMessage(globalMessage, 'Failed to load passkeys.', 'alert-danger'); |
| 34 | + } |
| 35 | + } |
| 36 | +} |
| 37 | + |
| 38 | +/** |
| 39 | + * Display credentials in UI. |
| 40 | + */ |
| 41 | +function displayCredentials(container, credentials) { |
| 42 | + if (credentials.length === 0) { |
| 43 | + container.innerHTML = '<p class="text-muted">No passkeys registered yet.</p>'; |
| 44 | + return; |
| 45 | + } |
| 46 | + |
| 47 | + container.innerHTML = credentials.map(cred => ` |
| 48 | + <div class="card mb-2" data-id="${escapeHtml(cred.id)}"> |
| 49 | + <div class="card-body d-flex justify-content-between align-items-center py-2"> |
| 50 | + <div> |
| 51 | + <strong>${escapeHtml(cred.label || 'Unnamed Passkey')}</strong> |
| 52 | + <br> |
| 53 | + <small class="text-muted"> |
| 54 | + Created: ${new Date(cred.created).toLocaleDateString()} |
| 55 | + ${cred.lastUsed ? ' | Last used: ' + new Date(cred.lastUsed).toLocaleDateString() : ' | Never used'} |
| 56 | + </small> |
| 57 | + <br> |
| 58 | + ${cred.backupEligible |
| 59 | + ? '<span class="badge bg-success">Synced</span>' |
| 60 | + : '<span class="badge bg-warning text-dark">Device-bound</span>'} |
| 61 | + </div> |
| 62 | + <div> |
| 63 | + <button class="btn btn-sm btn-outline-secondary me-1" onclick="window.renamePasskey('${escapeHtml(cred.id)}')"> |
| 64 | + <i class="bi bi-pencil"></i> Rename |
| 65 | + </button> |
| 66 | + <button class="btn btn-sm btn-outline-danger" onclick="window.deletePasskey('${escapeHtml(cred.id)}')"> |
| 67 | + <i class="bi bi-trash"></i> Delete |
| 68 | + </button> |
| 69 | + </div> |
| 70 | + </div> |
| 71 | + </div> |
| 72 | + `).join(''); |
| 73 | +} |
| 74 | + |
| 75 | +/** |
| 76 | + * Rename a passkey. |
| 77 | + */ |
| 78 | +async function renamePasskey(credentialId) { |
| 79 | + const newLabel = prompt('Enter new name for this passkey:'); |
| 80 | + if (!newLabel) return; |
| 81 | + |
| 82 | + const globalMessage = document.getElementById('passkeyMessage'); |
| 83 | + |
| 84 | + try { |
| 85 | + const response = await fetch(`/user/webauthn/credentials/${credentialId}/label`, { |
| 86 | + method: 'PUT', |
| 87 | + headers: { |
| 88 | + 'Content-Type': 'application/json', |
| 89 | + [csrfHeader]: csrfToken |
| 90 | + }, |
| 91 | + body: JSON.stringify({ label: newLabel }) |
| 92 | + }); |
| 93 | + |
| 94 | + if (!response.ok) { |
| 95 | + const data = await response.json(); |
| 96 | + throw new Error(data.message || 'Failed to rename passkey'); |
| 97 | + } |
| 98 | + |
| 99 | + if (globalMessage) { |
| 100 | + showMessage(globalMessage, 'Passkey renamed successfully.', 'alert-success'); |
| 101 | + } |
| 102 | + loadPasskeys(); |
| 103 | + } catch (error) { |
| 104 | + console.error('Failed to rename passkey:', error); |
| 105 | + if (globalMessage) { |
| 106 | + showMessage(globalMessage, error.message, 'alert-danger'); |
| 107 | + } |
| 108 | + } |
| 109 | +} |
| 110 | + |
| 111 | +/** |
| 112 | + * Delete a passkey with confirmation. |
| 113 | + */ |
| 114 | +async function deletePasskey(credentialId) { |
| 115 | + if (!confirm('Are you sure you want to delete this passkey? This action cannot be undone.')) { |
| 116 | + return; |
| 117 | + } |
| 118 | + |
| 119 | + const globalMessage = document.getElementById('passkeyMessage'); |
| 120 | + |
| 121 | + try { |
| 122 | + const response = await fetch(`/user/webauthn/credentials/${credentialId}`, { |
| 123 | + method: 'DELETE', |
| 124 | + headers: { [csrfHeader]: csrfToken } |
| 125 | + }); |
| 126 | + |
| 127 | + if (!response.ok) { |
| 128 | + const data = await response.json(); |
| 129 | + throw new Error(data.message || 'Failed to delete passkey'); |
| 130 | + } |
| 131 | + |
| 132 | + if (globalMessage) { |
| 133 | + showMessage(globalMessage, 'Passkey deleted successfully.', 'alert-success'); |
| 134 | + } |
| 135 | + loadPasskeys(); |
| 136 | + } catch (error) { |
| 137 | + console.error('Failed to delete passkey:', error); |
| 138 | + if (globalMessage) { |
| 139 | + showMessage(globalMessage, error.message, 'alert-danger'); |
| 140 | + } |
| 141 | + } |
| 142 | +} |
| 143 | + |
| 144 | +/** |
| 145 | + * Handle register passkey button click. |
| 146 | + */ |
| 147 | +async function handleRegisterPasskey() { |
| 148 | + const globalMessage = document.getElementById('passkeyMessage'); |
| 149 | + const labelInput = document.getElementById('passkeyLabel'); |
| 150 | + const label = labelInput ? labelInput.value.trim() : ''; |
| 151 | + |
| 152 | + try { |
| 153 | + await registerPasskey(label || 'My Passkey'); |
| 154 | + if (globalMessage) { |
| 155 | + showMessage(globalMessage, 'Passkey registered successfully!', 'alert-success'); |
| 156 | + } |
| 157 | + if (labelInput) labelInput.value = ''; |
| 158 | + loadPasskeys(); |
| 159 | + } catch (error) { |
| 160 | + console.error('Registration error:', error); |
| 161 | + if (globalMessage) { |
| 162 | + showMessage(globalMessage, 'Failed to register passkey: ' + error.message, 'alert-danger'); |
| 163 | + } |
| 164 | + } |
| 165 | +} |
| 166 | + |
| 167 | +// Expose to global scope for onclick handlers in the credential list |
| 168 | +window.renamePasskey = renamePasskey; |
| 169 | +window.deletePasskey = deletePasskey; |
| 170 | + |
| 171 | +// Initialize on page load |
| 172 | +document.addEventListener('DOMContentLoaded', async () => { |
| 173 | + const passkeySection = document.getElementById('passkey-section'); |
| 174 | + if (!passkeySection) return; |
| 175 | + |
| 176 | + if (!isWebAuthnSupported()) { |
| 177 | + passkeySection.innerHTML = '<div class="alert alert-warning">Your browser does not support passkeys.</div>'; |
| 178 | + return; |
| 179 | + } |
| 180 | + |
| 181 | + // Wire up register button |
| 182 | + const registerBtn = document.getElementById('registerPasskeyBtn'); |
| 183 | + if (registerBtn) { |
| 184 | + registerBtn.addEventListener('click', handleRegisterPasskey); |
| 185 | + } |
| 186 | + |
| 187 | + // Load existing passkeys |
| 188 | + loadPasskeys(); |
| 189 | +}); |
0 commit comments