Unable to add passkeys on selfhosted instance

(#584) Bug Fixed security self-hosting

Summary

Users are not able to add passkeys to log into their account on selfhosted instances.

Steps to reproduce

  1. Go to the account security settings
  2. Try to add a passkey
  3. Fails

Environment

Version: Latest from the repo OS: Windows Browser: Firefox Device: PC

Logs or screenshots

Relevant logs in the devtools console are these: [12:13:00] [SecurityTab] [Error] Failed to add passkey SecurityError: The RP ID "fluxer.app" is invalid for this domain It seems that the RP ID for the passkeys is hardcoded to fluxer.app as i haven't seen any parameters to modify to change it

4 comments

Sign in with Fluxer to comment and vote.
Comment by @creeperita09
RexSystem 1 vote originally by @creeperita09 on GitHub OP
Upon further inspection it does not seem to be hardcoded but it is not using the domain specified in the .env as the fluxer base domain
Comment by @Speykious
RexSystem 1 vote originally by @Speykious on GitHub
For anyone who wants the fix for this, you need to add this env variable in docker-compose.yaml:
FLUXER_PASSKEY_RP_NAME: ${FLUXER_PASSKEY_RP_NAME:-Fluxer}
FLUXER_PASSKEY_RP_ID: ${FLUXER_PASSKEY_RP_ID:-fluxer.app}
Note
(the Fluxer and fluxer.app values are just default values, you can set them to anything you want.)
Then, in .env, you can set FLUXER_PASSKEY_RP_NAME to whatever name you want and FLUXER_PASSKEY_RP_ID to your instance domain.
Comment by @BladeWDR
RexSystem 1 vote originally by @BladeWDR on GitHub
For anyone who wants the fix for this, you need to add this env variable in docker-compose.yaml: FLUXER_PASSKEY_RP_NAME: ${FLUXER_PASSKEY_RP_NAME:-Fluxer} FLUXER_PASSKEY_RP_ID: ${FLUXER_PASSKEY_RP_ID:-fluxer.app} Note (the Fluxer and fluxer.app values are just default values, you can set them to anything you want.) Then, in .env, you can set FLUXER_PASSKEY_RP_NAME to whatever name you want and FLUXER_PASSKEY_RP_ID to your instance domain.
Tried doing this it's still erroring out. "Failed to verify WebAuthn credential." EDIT: I figured this out - I had to add my domain to this environment variable: FLUXER_PASSKEY_ADDITIONAL_ALLOWED_ORIGINS. Man this project could use some better docs around configuration.
Comment by Tarek
TarekMod 1 vote originally by @Taarek on GitHub
> For anyone who wants the fix for this, you need to add this env variable in docker-compose.yaml: > FLUXER_PASSKEY_RP_NAME: ${FLUXER_PASSKEY_RP_NAME:-Fluxer} > FLUXER_PASSKEY_RP_ID: ${FLUXER_PASSKEY_RP_ID:-fluxer.app} > Note > (the Fluxer and fluxer.app values are just default values, you can set them to anything you want.) > Then, in .env, you can set FLUXER_PASSKEY_RP_NAME to whatever name you want and FLUXER_PASSKEY_RP_ID to your instance domain.
>
EDIT: I figured this out - I had to add my domain to this environment variable: FLUXER_PASSKEY_ADDITIONAL_ALLOWED_ORIGINS. Man this project could use some better docs around configuration.
The docs are open source, PRs are welcome and encouraged! See https://github.com/fluxerapp/fluxer/tree/main/fluxer_docs/docs/operator