Expand description
Managing a post-quantum account’s sign-in factors Managing a post-quantum account’s sign-in factors from an authenticated session: list, add a security key, rename, remove, set the policy, regenerate the recovery codes.
Every change carries a fresh step-up (the account’s factors, proven again, bound to the change) except in a session signed in with a recovery code, which may only add a key and set the policy.
let (key, mut touches) = security_key_channel();
// Serve `touches` by running WebAuthn `get` with the PRF extension, then answering.
let step_up = SignInFactors::password("hunter2").with_security_key(key);
let op = SignInManagementOp::AddSecurityKey { credential_id: vec![1, 2, 3], label: "YubiKey".into() };
let added = conn.manage_sign_in(op, step_up).await?;