Skip to content

Spike: compile webauthn-rs and openidconnect to wasm32 for Workers #2

Description

@ParallelEntrepreneur

Part of #1.

Blocked by: none. Blocks both passkey issues.

Known before the spike starts. On 2026-09-06 a scratch crate with webauthn-rs = "0.5" resolved to 0.5.5 and pulled openssl 0.10 and openssl-sys through webauthn-rs-core and webauthn-attestation-ca. webauthn-rs-core 0.5 has no features at all, so there is nothing to switch off. It cannot build for wasm32-unknown-unknown. In the same scratch crate, openidconnect 4.0 and oauth2 5.0 with default-features = false, plus argon2 0.6, built to wasm32 cleanly with no openssl, reqwest, tokio or mio in the tree, using getrandom with its wasm feature.

Problem. Passkeys need a relying-party implementation that runs in a Worker. The named crate does not. The OIDC crate does, but only through its bring-your-own HTTP client interface, which has to be wired to the harness HttpClient port.

Proposed approach.

  • Try webauthn-rs from its main branch (0.6 pre-release) and report whether the OpenSSL dependency is gone or made optional; if it builds to wasm32 and its API is stable enough, pin the git revision and record the risk.
  • Otherwise implement relying-party verification directly on pure-Rust crates: webauthn-rs-proto for the wire types, ciborium or coset for CBOR and COSE keys, p256, rsa and ed25519-dalek for signature verification, sha2 for the client-data hash. Scope it to the two ceremonies we need with attestation format none accepted and other formats stored but not verified, which is what consumer relying parties do. Estimate the size; it is expected to be a few hundred lines plus tests against the WebAuthn spec's test vectors.
  • Wire openidconnect to the harness HttpClient port through its AsyncHttpClient trait and prove discovery, token exchange and ID-token verification for Google inside wrangler dev.
  • Confirm argon2 runs within the Worker CPU budget: measure Argon2id at a few parameter sets in wrangler dev and on a deployed staging Worker, since wasm is slower than native and the paid plan's CPU limit is the constraint.

Acceptance criteria

  • A scratch venture in spikes/wasm-auth that builds with worker-build --release and runs under wrangler dev
  • Written result for webauthn-rs main: builds or not, and why
  • If not, a written design and size estimate for the pure-Rust verification path, with the crates pinned
  • openidconnect discovery and token exchange working against Google through the HttpClient port in wrangler dev
  • A table of argon2 parameter sets with measured wall and CPU time in wasm, and a recommended set
  • An ADR in the auth repo recording all four outcomes

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    authshared authentication servicespiketime-boxed investigation with a written recommendation

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions