feat(user): allow renaming security keys (webauthn/passkey) (#39413)

Closes https://github.com/go-gitea/gitea/issues/39287

Security key nicknames could only be set at registration, so a skipped
nickname left an auto-generated hex name until the key was
re-registered. Each key now has a Rename button opening a dialog with
the current nickname. A nickname used by another of the user's keys
(case-insensitive) or a blank nickname is rejected. Renames are recorded
as `user:webauth:rename` audit events.

Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
authored and GitHub committed 2026-10-05 19:12:22 +02:00
1 parent 66546045b5
commit d16b20b972
17 files changed
+142 -21

No files matched your search

+8 -1
View File
@@ -287,7 +287,14 @@ type TwoFactorScratchAuthForm struct {
// WebauthnRegistrationForm for reserving an WebAuthn name
type WebauthnRegistrationForm struct {
middleware.FormDefaultValidator
Name string `binding:"Required"`
Name string `binding:"TrimSpace;MaxSize(255)"`
}
// WebauthnRenameForm for renaming a WebAuthn credential
type WebauthnRenameForm struct {
middleware.FormDefaultValidator
ID int64 `binding:"Required"`
Name string `binding:"TrimSpace;Required;MaxSize(255)"`
}
// PackageSettingForm form for package settings