/*
Copyright (C) 2023-2026 QuantumNous
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as
published by the Free Software Foundation, either version 3 of the
License, or (at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU Affero General Public License for more details.
You should have received a copy of the GNU Affero General Public License
along with this program. If not, see .
For commercial licensing, please contact support@quantumnous.com
*/
import { api } from '@/lib/api'
import type {
SecurityProof,
SecurityProofScope,
} from '../secure-verification/types'
import type { ApiResponse, PasskeyOptionsPayload, PasskeyStatus } from './types'
function proofHeaders(proofToken?: string): Record | undefined {
return proofToken ? { 'X-Security-Proof': proofToken } : undefined
}
export async function getPasskeyStatus(): Promise> {
const res = await api.get>('/api/user/passkey')
return res.data
}
export async function beginPasskeyRegistration(
proofToken?: string
): Promise> {
const res = await api.post>(
'/api/user/passkey/register/begin',
undefined,
{ headers: proofHeaders(proofToken) }
)
return res.data
}
export async function finishPasskeyRegistration(
flowToken: string,
payload: Record,
proofToken?: string
): Promise {
const res = await api.post(
'/api/user/passkey/register/finish',
{
flow_token: flowToken,
credential: payload,
},
{ headers: proofHeaders(proofToken), acceptAuthRotation: true }
)
return res.data
}
export async function deletePasskey(proofToken?: string): Promise {
const res = await api.delete('/api/user/passkey', {
headers: proofHeaders(proofToken),
acceptAuthRotation: true,
})
return res.data
}
export async function beginPasskeyLogin(): Promise<
ApiResponse
> {
const res = await api.post>(
'/api/user/passkey/login/begin'
)
return res.data
}
export async function finishPasskeyLogin(
flowToken: string,
payload: Record
): Promise {
const res = await api.post(
'/api/user/passkey/login/finish',
{ flow_token: flowToken, credential: payload },
{ skipAuthRefresh: true }
)
return res.data
}
export async function beginPasskeyVerification(
scope: SecurityProofScope
): Promise> {
const res = await api.post>(
'/api/user/passkey/verify/begin',
{ scope }
)
return res.data
}
export async function finishPasskeyVerification(
flowToken: string,
payload: Record
): Promise> {
const res = await api.post>(
'/api/user/passkey/verify/finish',
{ flow_token: flowToken, credential: payload }
)
return res.data
}