Codeberg/Community
54
325
Fork
You've already forked Community
12

Unable to authenticate via Webauthn #993

Open
opened 2023年04月16日 14:25:26 +02:00 by Marix · 6 comments

Hi,

As of recently I am no longer able to authenticate via Webauthn but have to utilise the backup method of using a TOTP code. On either of my two Solo keys I get the following error message that I also attached as a screenshot:

Dein Sicherheitsschlüssel konnte nicht gelesen werden.
An attempt was made to use an object that is not, or is no longer, usable

I checked with other sites like Github and it seems the only page on which Webauthn is broken for me is Codeberg. Thus, it seems I either managed to break solely that single slot on both of my keys or something has broken on the server side since I registered them last year.

I have not yet tried re-registering the keys as I did not want to change the broken state in case there is any specific information you wanted to gather first. Otherwise that would be the next thing I'd try.

Hi, As of recently I am no longer able to authenticate via Webauthn but have to utilise the backup method of using a TOTP code. On either of my two Solo keys I get the following error message that I also attached as a screenshot: > Dein Sicherheitsschlüssel konnte nicht gelesen werden. > An attempt was made to use an object that is not, or is no longer, usable I checked with other sites like Github and it seems the only page on which Webauthn is broken for me is Codeberg. Thus, it seems I either managed to break solely that single slot on both of my keys or something has broken on the server side since I registered them last year. I have not yet tried re-registering the keys as I did not want to change the broken state in case there is any specific information you wanted to gather first. Otherwise that would be the next thing I'd try.

Eh.. to help anybody maybe investigating an issue:

Which OS and browser are you using?

Maybe some of the Forgejo devs know, if it could be related to Gitea deprecating U2F in favor of WebAuthn (last year) and Firefox also disabled U2F in favor of WebAuthn in their recent release?

Eh.. to help anybody maybe investigating an issue: Which OS and browser are you using? Maybe some of the Forgejo devs know, if it could be related to Gitea deprecating U2F in favor of WebAuthn (last year) and Firefox also disabled U2F in favor of WebAuthn in their recent release?
Author
Copy link

That is an excellent question. I am using Firefox 102.10.0esr on openSUSE Leap 15.4.

That is an excellent question. I am using Firefox 102.10.0esr on openSUSE Leap 15.4.

Could you try on Chromium, for example?

Could you try on Chromium, for example?
Author
Copy link

So I tried with Chromium, and curiously that gives me a slightly different error message, telling me that my key is not registered on that site.

With Chromium, too, the keys work on other sites.

So I tried with Chromium, and curiously that gives me a slightly different error message, telling me that my key is not registered on that site. With Chromium, too, the keys work on other sites.

https://github.com/go-gitea/gitea/pull/22697 might be related, I'm not sure.

https://github.com/go-gitea/gitea/pull/22697 might be related, I'm not sure.

Hesitantly adding upstream tag.

Hesitantly adding upstream tag.
Sign in to join this conversation.
No Branch/Tag specified
main
No results found.
Labels
Clear labels
accessibility

Reduces accessibility and is thus a "bug" for certain user groups on Codeberg.
bug

Something is not working the way it should. Does not concern outages.
bug
infrastructure

Errors evidently caused by infrastructure malfunctions or outages
Codeberg

This issue involves Codeberg's downstream modifications and settings and/or Codeberg's structures.
contributions welcome

Please join the discussion and consider contributing a PR!
docs

No bug, but an improvement to the docs or UI description will help
duplicate

This issue or pull request already exists
enhancement

New feature
infrastructure

Involves changes to the server setups, use `bug/infrastructure` for infrastructure-related user errors.
legal

An issue directly involving legal compliance
licence / ToS

involving questions about the ToS, especially licencing compliance
please chill
we are volunteers

Please consider editing your posts and remember that there is a human on the other side. We get that you are frustrated, but it's harder for us to help you this way.
public relations

Things related to Codeberg's external communication
question

More information is needed
question
user support

This issue contains a clearly stated problem. However, it is not clear whether we have to fix anything on Codeberg's end, but we're helping them fix it and/or find the cause.
s/Forgejo

Related to Forgejo. Please also check Forgejo's issue tracker.
s/Forgejo/migration

Migration related issues in Forgejo
s/Pages

Issues related to the Codeberg Pages feature
s/Weblate

Issue is related to the Weblate instance at https://translate.codeberg.org
s/Woodpecker

Woodpecker CI related issue
security

involves improvements to the sites security
service

Add a new service to the Codeberg ecosystem (instead of implementing into Gitea)
upstream

An open issue or pull request to an upstream repository to fix this issue (partially or completely) exists (i.e. Gitea, Forgejo, etc.)
wontfix

Codeberg's current set of contributors are not planning to spend time on delegating this issue.
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
5 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Codeberg/Community#993
Reference in a new issue
Codeberg/Community
No description provided.
Delete branch "%!s()"

Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?