* Expose authenticator AAGUID as Guid instead of raw bytes
The Win32 WebAuthNGetAuthenticatorList API returns the authenticator
identifier as a big-endian encoded GUID, which is in fact the
Authenticator Attestation GUID (AAGUID). Decode it into a Guid in the
wrapper instead of surfacing the raw bytes (previously Base64Url-encoded
in the UI and PowerShell output).
- Rename AuthenticatorDetails.AuthenticatorId (byte[]) to AaGuid (Guid)
and decode the big-endian bytes in ApiHelper.Translate.
- Display the value as a GUID in the PasskeyUI authenticator list,
renaming the column to 'AAGUID'.
- Update the Get-PasskeyAuthenticator format views accordingly.
- Update API docs and CHANGELOG.
* Remove unused EndianBitConverter helper
EndianBitConverter was dead code: all of its members (ToUInt32BigEndian,
ToUInt16BigEndian, ToGuidBigEndian, SwapBytes) were only referenced
within the file itself. Big-endian GUID decoding now goes through the
GuidPolyfill.Create helper used elsewhere in the codebase.
* Make AuthenticatorDetails.AaGuid nullable
Return null instead of Guid.Empty when the Win32 API does not provide a
valid 16-byte authenticator identifier, so the absence of an AAGUID is
represented distinctly rather than as an all-zero GUID.
---------
Co-authored-by: Claude <noreply@anthropic.com>
- Move UserId, UserName, UserDisplayName from WebAuthnOperation base class
to WebAuthnAttestationOperation where they belong (registration-only fields)
- Add missing ReadEndMap() call in CtapMakeCredentialRequestParser.ReadUserMap
to leave the CBOR reader in a consistent state
- Remove JsonSerializerIsReflectionEnabledByDefault=false from
Directory.Build.props as most serialization call sites lack source-generated
contexts and would throw NotSupportedException at runtime
- Fix CtapCommandEvent.Command type from int? to string? and parse with
GetString instead of GetInt32, matching the actual event log data
- Update CtapCommandEvent doc samples and add known command name list
based on local event log observations
- Use completed event timestamp for TimeCompleted when available, falling
back to max timestamp across all events
- Rename EndTime to TimeCompleted for consistency with TimeStarted
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Introduce DSInternals.Win32.WebAuthn.Events library that reads and parses
events from the Microsoft-Windows-WebAuthN/Operational event log. Includes
typed event models for all known event IDs, CTAP2 CBOR request parsing
(via System.Formats.Cbor) for extracting user info, and aggregation of
related events into WebAuthnOperation objects grouped by transaction ID.
Add Event Log tab to PasskeyUI with a DataGrid displaying successful
registration and authentication operations with copiable fields.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Implement certificate-based software signing for WebAuthn attestation
and assertion flows, enabling offline testing without a physical
authenticator or the Windows WebAuthn API.
New features:
- SoftwareAuthenticator: core signing logic for packed self-attestation
and assertion responses using PEM private keys (EC and RSA)
- Attestation and assertion signing dialogs with authenticator presets
(YubiKey 5 NFC, Windows Hello, 1Password, Bitwarden, etc.)
- KeePassXC .passkey file import with RP ID validation and auto-fill
- Key pair generation and PEM export for all supported COSE algorithms
- Cross-dialog caching of authenticator parameters
- AAGUID/key file validation rules and Fluent Icons on buttons
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The enum values (None=0, VendorFacilitated=1, PlatformManaged=2) are
mutually exclusive attestation levels per the FIDO spec, not combinable
bit flags.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Base url is computed within Invoke-MgGraphRequest, no need to build or supply it in the request.
Add Import-Module for Microsoft.Graph.Identity.SignIns to prevent "InvalidOperation: Unable to find type [Microsoft.Graph.PowerShell.Models.MicrosoftGraphFido2AuthenticationMethod]" error when trying to register a passkey.