用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/aibot88/sec_skill_store --skill fido2命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
基于 SOC 职业分类
| name | fido2 |
| description | FIDO2/WebAuthn/パスキー関連の実装・設定・ドキュメント・テストを扱う時に使用。パスキー登録、認証、管理、アテステーション検証に関する作業で自動的に呼び出される。 |
| argument-hint | ["作業内容の説明"] |
idp-serverにおけるFIDO2/WebAuthn/パスキー実装のコンテキスト情報。
クライアント (sample-web)
│
├── navigator.credentials.create() / get()
│
▼
idp-server (認可フロー内)
│
├── WebAuthn4jRegistrationManager (登録)
├── WebAuthn4jAuthenticationManager (認証)
│
▼
WebAuthn4j ライブラリ (内部統合)
重要: 外部FIDO2サーバーではなく、WebAuthn4jライブラリを内部統合。
| ファイル | 役割 |
|---|---|
libs/idp-server-webauthn4j-adapter/.../WebAuthn4jRegistrationManager.java | 登録処理・アテステーション検証 |
libs/idp-server-webauthn4j-adapter/.../WebAuthn4jAuthenticationManager.java | 認証処理・署名検証 |
libs/idp-server-webauthn4j-adapter/.../WebAuthn4jConfiguration.java | 設定パース |
libs/idp-server-webauthn4j-adapter/.../WebAuthn4jManagerFactory.java | Manager生成 |
| ファイル | 内容 |
|---|---|
documentation/.../fido2/01-registration.md | パスキー登録設定 |
documentation/.../fido2/02-authentication.md | パスキー認証設定 |
documentation/.../fido2/03-management.md | パスキー管理API |
documentation/.../fido2/04-attestation-verification.md | アテステーション検証 |
| ファイル | 内容 |
|---|---|
e2e/src/tests/usecase/mfa/mfa-05-fido2.test.js | FIDO2基本フロー |
e2e/src/tests/usecase/mfa/mfa-06-fido2-attestation-verification.test.js | アテステーション検証 |
e2e/src/lib/fido/fido2.js | テスト用FIDO2ヘルパー |
| ファイル | 内容 |
|---|---|
sample-web/src/components/PasskeyRegistration.tsx | 登録UI |
sample-web/src/components/PasskeyAuthentication.tsx | 認証UI |
sample-web/src/components/UserInfo.tsx | デバイス一覧表示 |
| interaction | function | 用途 |
|---|---|---|
fido2-registration-challenge | webauthn4j_registration_challenge | 登録チャレンジ発行 |
fido2-registration | webauthn4j_registration | 登録完了・検証 |
fido2-authentication-challenge | webauthn4j_authentication_challenge | 認証チャレンジ発行 |
fido2-authentication | webauthn4j_authentication | 認証完了・検証 |
{
"rp_id": "example.com",
"origin": "https://example.com",
"rp_name": "My Service",
"require_resident_key": true,
"user_verification_required": true
}
| モード | 設定 | 用途 |
|---|---|---|
| なし | attestation_preference: "none" | 開発・一般向け |
| TrustStore | trust_store_path: "/path/to/truststore.p12" | 特定ベンダー限定 |
| FIDO MDS | mds.enabled: true | 本番・高セキュリティ |
{
"rp_id": "example.com",
"allowed_origins": [
"https://app.example.com",
"https://www.example.com"
]
}
{
"success_conditions": {
"any_of": [
[{ "path": "$.password-authentication.success_count", "operation": "gte", "value": 1 }],
[{ "path": "$.fido2-authentication.success_count", "operation": "gte", "value": 1 }]
]
}
}
パスキー一覧は ID Token / Userinfo の authentication_devices クレーム から取得。
custom_claims_scope_mapping: truescope: "openid claims:authentication_devices"scope=openid+claims:authentication_devicesWebAuthn4j*Manager.java に処理追加WebAuthn4jConfiguration.java に設定追加04-attestation-verification.md で設定例確認WebAuthn4jConfiguration.java でパース確認$ARGUMENTS