From 5604917064e69efdfb0982f500ad0d8cd7f96b77 Mon Sep 17 00:00:00 2001 From: Bryan Brooks Date: Wed, 25 Feb 2026 12:37:22 -0600 Subject: [PATCH] fix: passkey auth client unwraps options from API response The /auth/passkey/authenticate/options endpoint returns {success, options: {...}} but the login page JS was reading opts.challenge directly instead of opts.options.challenge, causing the WebAuthn ceremony to fail with undefined values. --- gateway/src/routes/oidc/authorize.ts | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/gateway/src/routes/oidc/authorize.ts b/gateway/src/routes/oidc/authorize.ts index 2edb6f7..9ca7f38 100644 --- a/gateway/src/routes/oidc/authorize.ts +++ b/gateway/src/routes/oidc/authorize.ts @@ -222,7 +222,8 @@ export function createAuthorizeRouter( body: JSON.stringify({}) }) .then(function(r) { return r.json(); }) - .then(function(opts) { + .then(function(data) { + var opts = data.options || data; var pubKeyOpts = { challenge: b64urlToBuffer(opts.challenge), timeout: opts.timeout, -- 2.51.2