Skip to content

fix: Prevent from sending username on passkey login challenge - #175

Open
tanya732 wants to merge 4 commits into
mainfrom
fix/passkey-login-challenge-username-deprecate
Open

tanya732 wants to merge 4 commits into
mainfrom
fix/passkey-login-challenge-username-deprecate

Conversation

@tanya732

@tanya732 tanya732 commented Sep 25, 2026 •

Copy link
Copy Markdown

Summary

passkey_login_challenge forwarded username into the POST /passkey/challenge request body, but Auth0 rejects it with "username" is not allowed (passkey_challenge_failed, purpose login). Per the Auth0 passkey APIs reference, the login challenge body accepts only client_id, optional realm, and organization never username. On login the user is identified by the credential they select in the browser prompt, so no username is needed.

This stops forwarding username while keeping the parameter in the signature for backward compatibility (non-breaking). Passing it now emits a DeprecationWarning; it will be removed in a future major release.

Changes

  • src/auth0_server_python/auth_server/server_client.py - passkey_login_challenge:
    • Removed if username: body["username"] = username - username is no longer added to the request body.
    • Emits a DeprecationWarning when username is not None.
    • Updated the docstring: username is documented as deprecated/ignored, with the reason.
    • Signature unchanged → non-breaking.
  • src/auth0_server_python/tests/test_server_client.py - renamed test_passkey_login_challenge_with_username → test_passkey_login_challenge_ignores_username; now asserts "username" not in body and wraps the call in pytest.warns(DeprecationWarning).
  • examples/Passkeys.md - removed the username=... argument and the "conditional-UI hint" note from the login example; the prose now explains the selected credential identifies the user, so the login challenge takes no username.

Reference

doc

###Testing

  • poetry run pytest -k passkey → 49 passed.
  • poetry run ruff check on changed files → clean.

Breaking change?

No. The username parameter is retained; only its behavior changes (ignored + deprecation warning instead of forwarded-and-rejected).

@tanya732
tanya732 marked this pull request as ready for review September 25, 2026 15:41
@tanya732
tanya732 requested a review from a team as a code owner September 25, 2026 15:41

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants