From e75d24f287effd5178b4bc87850b8d10610f40f4 Mon Sep 17 00:00:00 2001 From: Bewinxed Date: Fri, 10 Oct 2025 17:26:02 +0300 Subject: [PATCH] fix(auth): use direct attestation for registration/authentication --- packages/core/auth-js/src/lib/webauthn.ts | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/packages/core/auth-js/src/lib/webauthn.ts b/packages/core/auth-js/src/lib/webauthn.ts index b416db539..ebd286acb 100644 --- a/packages/core/auth-js/src/lib/webauthn.ts +++ b/packages/core/auth-js/src/lib/webauthn.ts @@ -462,13 +462,14 @@ export const DEFAULT_CREATION_OPTIONS: Partial = { /** set to preferred because older yubikeys don't have PIN/Biometric */ userVerification: 'preferred', hints: ['security-key'], + attestation: 'direct', } function deepMerge(...sources: Partial[]): T {