114 Commits
Author SHA1 Message Date
Michael Grafnetter 2d23b60336 GetAssertion parsing 2026-06-19 20:33:28 +02:00
Michael Grafnetter 85ef23e8a7 Credential event parsing 2026-06-18 01:54:15 +02:00
Michael Grafnetter 5f67922884 Expose additional passkey properties 2026-06-17 22:49:33 +02:00
Michael Grafnetter 2f2a28ed26 Prepare for release 3.2 v3.2 2026-06-04 22:21:31 +02:00
Michael GrafnetterandClaude 3a05986c82 Expose authenticator AAGUID as Guid instead of raw bytes (#43)
* Expose authenticator AAGUID as Guid instead of raw bytes

The Win32 WebAuthNGetAuthenticatorList API returns the authenticator
identifier as a big-endian encoded GUID, which is in fact the
Authenticator Attestation GUID (AAGUID). Decode it into a Guid in the
wrapper instead of surfacing the raw bytes (previously Base64Url-encoded
in the UI and PowerShell output).

- Rename AuthenticatorDetails.AuthenticatorId (byte[]) to AaGuid (Guid)
  and decode the big-endian bytes in ApiHelper.Translate.
- Display the value as a GUID in the PasskeyUI authenticator list,
  renaming the column to 'AAGUID'.
- Update the Get-PasskeyAuthenticator format views accordingly.
- Update API docs and CHANGELOG.

* Remove unused EndianBitConverter helper

EndianBitConverter was dead code: all of its members (ToUInt32BigEndian,
ToUInt16BigEndian, ToGuidBigEndian, SwapBytes) were only referenced
within the file itself. Big-endian GUID decoding now goes through the
GuidPolyfill.Create helper used elsewhere in the codebase.

* Make AuthenticatorDetails.AaGuid nullable

Return null instead of Guid.Empty when the Win32 API does not provide a
valid 16-byte authenticator identifier, so the absence of an AAGUID is
represented distinctly rather than as an all-zero GUID.

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-06-04 21:58:45 +02:00
Michael Grafnetter 2265792276 Prefer native JSON responses 2026-06-04 17:33:09 +02:00
Michael Grafnetter 93472b72a2 Added -BrowserInPrivateMode support in PS 2026-05-29 20:12:53 +02:00
Michael Grafnetter 33172625a0 Resolve package issue 2026-05-14 15:13:44 +02:00
Michael Grafnetter a9ebfb9733 Resolve some compilation warnings 2026-05-14 15:04:46 +02:00
Michael GrafnetterandCopilot 4682a07063 Fix build and test on new machines
Co-authored-by: Copilot <copilot@github.com>
v3.1
2026-05-14 13:25:12 +02:00
Michael Grafnetter f00f4e0dab Fix module description 2026-05-14 12:40:52 +02:00
Michael Grafnetter 9d3d091283 Prepeare for release 3.1 2026-05-14 12:30:21 +02:00
Michael Grafnetter 642eda9be2 Exposed HostName param through PS 2026-05-13 21:09:01 +02:00
Michael Grafnetter f6596aa4a2 Documentation update 2026-05-13 20:09:02 +02:00
Michael GrafnetterandCopilot b83be00fcf Fix passkey cloud registration issues
Co-authored-by: Copilot <copilot@github.com>
2026-05-12 16:52:23 +02:00
Michael Grafnetter 90093e8db2 Improved adapter 2026-05-11 12:45:07 +02:00
Michael Grafnetter 3e2d991600 Mediation enum 2026-05-11 12:44:46 +02:00
Michael Grafnetter d7054dbc4d WebAuthn switched to AsyncDelegateCommand in WPF v3.0 2026-05-09 23:52:15 +02:00
Michael Grafnetter 5f70de6331 Version 3 (#42)
- Data model improvements
- Password manager export parsers
2026-05-07 22:35:01 +02:00
Michael Grafnetter abf150db9f Additional constants 2026-04-05 21:29:51 +02:00
Michael Grafnetter feb72a0d62 Fix PS views v2.1.1 2026-04-05 18:00:23 +02:00
Michael Grafnetter 7c96322cfb Fix ConvertFrom-Base64UrlParameter tests v2.1 2026-04-05 17:11:42 +02:00
Michael Grafnetter a6939cf3eb Release 2.1 2026-04-05 15:02:20 +02:00
Michael Grafnetter 3e914e3ab5 Fix signing and workflow permissions v2.0 2026-04-03 11:50:59 +02:00
Michael Grafnetter 950f965e2b Update signing method to use Azure Key Vault 2026-04-03 10:43:24 +02:00
Michael Grafnetter f3e9290984 Version 2 (#41)
* Fix workflows
* Remvoed PeterO.Cbor dependency
2026-04-03 10:22:35 +02:00
Michael GrafnetterandCopilot 36133f1e48 Fix module build (#40)
* Fix module build

* Update Src/DSInternals.Passkeys/Tests/Okta.Tests.ps1

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update Src/DSInternals.Passkeys/Tests/EntraID.Tests.ps1

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update Src/DSInternals.Passkeys/Tests/Okta.Tests.ps1

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update Src/DSInternals.Passkeys/Tests/EntraID.Tests.ps1

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-03-26 07:44:33 +01:00
Michael Grafnetter c64838c128 Fixed failing tests 2026-03-25 11:50:11 -07:00
Michael Grafnetter 5a85972fe4 Fix workflows 2026-03-11 18:12:17 +01:00
Michael Grafnetter acd425e321 Improve signing UX and refine event model 2026-03-11 17:50:39 +01:00
Michael Grafnetter cf246100ba Fixed compilation warnings 2026-03-11 09:42:18 +01:00
Michael GrafnetterandClaude Opus 4.6 ee3eb077c3 Fix event model issues and improve domain correctness
- Move UserId, UserName, UserDisplayName from WebAuthnOperation base class
  to WebAuthnAttestationOperation where they belong (registration-only fields)
- Add missing ReadEndMap() call in CtapMakeCredentialRequestParser.ReadUserMap
  to leave the CBOR reader in a consistent state
- Remove JsonSerializerIsReflectionEnabledByDefault=false from
  Directory.Build.props as most serialization call sites lack source-generated
  contexts and would throw NotSupportedException at runtime
- Fix CtapCommandEvent.Command type from int? to string? and parse with
  GetString instead of GetInt32, matching the actual event log data
- Update CtapCommandEvent doc samples and add known command name list
  based on local event log observations
- Use completed event timestamp for TimeCompleted when available, falling
  back to max timestamp across all events
- Rename EndTime to TimeCompleted for consistency with TimeStarted

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-10 17:24:26 +01:00
Michael GrafnetterandClaude Opus 4.6 3f6b70067d Add WebAuthn event log reader project and Event Log tab in PasskeyUI
Introduce DSInternals.Win32.WebAuthn.Events library that reads and parses
events from the Microsoft-Windows-WebAuthN/Operational event log. Includes
typed event models for all known event IDs, CTAP2 CBOR request parsing
(via System.Formats.Cbor) for extracting user info, and aggregation of
related events into WebAuthnOperation objects grouped by transaction ID.

Add Event Log tab to PasskeyUI with a DataGrid displaying successful
registration and authentication operations with copiable fields.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-10 14:44:20 +01:00
Michael GrafnetterandClaude Opus 4.6 13dfdbf177 Add software-based signing to Passkey UI
Implement certificate-based software signing for WebAuthn attestation
and assertion flows, enabling offline testing without a physical
authenticator or the Windows WebAuthn API.

New features:
- SoftwareAuthenticator: core signing logic for packed self-attestation
  and assertion responses using PEM private keys (EC and RSA)
- Attestation and assertion signing dialogs with authenticator presets
  (YubiKey 5 NFC, Windows Hello, 1Password, Bitwarden, etc.)
- KeePassXC .passkey file import with RP ID validation and auto-fill
- Key pair generation and PEM export for all supported COSE algorithms
- Cross-dialog caching of authenticator parameters
- AAGUID/key file validation rules and Fluent Icons on buttons

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-10 14:20:21 +01:00
Michael GrafnetterandClaude Opus 4.6 a965a72d4d Remove incorrect [Flags] attribute from EnterpriseAttestationType
The enum values (None=0, VendorFacilitated=1, PlatformManaged=2) are
mutually exclusive attestation levels per the FIDO spec, not combinable
bit flags.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-10 14:15:56 +01:00
Michael Grafnetter 4fbd4f0cfb Improve JSON serialization and UI 2026-01-26 16:33:36 +01:00
Michael Grafnetter 19a279bad3 Updated paths in configs 2026-01-15 11:55:33 +01:00
Michael Grafnetter 2fcdbc5ef6 Added V9 API cmdlets 2026-01-14 17:25:22 +01:00
Michael Grafnetter ede0aae148 Finished upgrade to API v9 2026-01-11 22:34:39 +01:00
Michael Grafnetter 3eb503ec0a Updated API support to V9 2026-01-10 02:13:21 +01:00
Michael Grafnetter 983768ef65 Project structure modernization 2026-01-09 12:28:58 +01:00
Alex Seigler d31b92bc9e Move padding number suffix workaround 2025-11-17 23:06:47 +01:00
Alex Seigler 7fee5c4322 Add support for Okta (#18) 2025-01-16 15:29:49 +01:00
Michael Grafnetter 92fbd8078e Prepare for release 1.0.6 v1.0.6 2025-01-16 11:16:23 +01:00
Michael Grafnetter b68f1b1ece Added missing conditions to signing 2025-01-15 19:49:49 +01:00
Alex Seigler 3a4003a8a1 Compensate for corrupted base64 padding 2025-01-15 19:25:59 +01:00
Michael Grafnetter 2ab380f046 Change some signing secrets to variables 2025-01-05 14:10:55 +01:00
Alex Seigler 29dcb90f14 Remove base url building logic
Base url is computed within Invoke-MgGraphRequest, no need to build or supply it in the request.

Add Import-Module for Microsoft.Graph.Identity.SignIns to prevent "InvalidOperation: Unable to find type [Microsoft.Graph.PowerShell.Models.MicrosoftGraphFido2AuthenticationMethod]" error when trying to register a passkey.
2024-11-28 11:00:00 +01:00
Michael Grafnetter 7e68330740 Resolved #19: Outdated links in README v1.0.5 2024-11-14 17:24:59 +01:00
Michael Grafnetter ebe5fb5d7d Resolved #20: Incorrect DeletePlatformCredential signature 2024-11-14 17:15:56 +01:00