Part of #1.
Blocked by: none. Blocks both passkey issues.
Known before the spike starts. On 2026-09-06 a scratch crate with webauthn-rs = "0.5" resolved to 0.5.5 and pulled openssl 0.10 and openssl-sys through webauthn-rs-core and webauthn-attestation-ca. webauthn-rs-core 0.5 has no features at all, so there is nothing to switch off. It cannot build for wasm32-unknown-unknown. In the same scratch crate, openidconnect 4.0 and oauth2 5.0 with default-features = false, plus argon2 0.6, built to wasm32 cleanly with no openssl, reqwest, tokio or mio in the tree, using getrandom with its wasm feature.
Problem. Passkeys need a relying-party implementation that runs in a Worker. The named crate does not. The OIDC crate does, but only through its bring-your-own HTTP client interface, which has to be wired to the harness HttpClient port.
Proposed approach.
- Try
webauthn-rs from its main branch (0.6 pre-release) and report whether the OpenSSL dependency is gone or made optional; if it builds to wasm32 and its API is stable enough, pin the git revision and record the risk.
- Otherwise implement relying-party verification directly on pure-Rust crates:
webauthn-rs-proto for the wire types, ciborium or coset for CBOR and COSE keys, p256, rsa and ed25519-dalek for signature verification, sha2 for the client-data hash. Scope it to the two ceremonies we need with attestation format none accepted and other formats stored but not verified, which is what consumer relying parties do. Estimate the size; it is expected to be a few hundred lines plus tests against the WebAuthn spec's test vectors.
- Wire
openidconnect to the harness HttpClient port through its AsyncHttpClient trait and prove discovery, token exchange and ID-token verification for Google inside wrangler dev.
- Confirm
argon2 runs within the Worker CPU budget: measure Argon2id at a few parameter sets in wrangler dev and on a deployed staging Worker, since wasm is slower than native and the paid plan's CPU limit is the constraint.
Acceptance criteria
Part of #1.
Blocked by: none. Blocks both passkey issues.
Known before the spike starts. On 2026-09-06 a scratch crate with
webauthn-rs = "0.5"resolved to 0.5.5 and pulledopenssl0.10 andopenssl-systhroughwebauthn-rs-coreandwebauthn-attestation-ca.webauthn-rs-core0.5 has no features at all, so there is nothing to switch off. It cannot build forwasm32-unknown-unknown. In the same scratch crate,openidconnect4.0 andoauth25.0 withdefault-features = false, plusargon20.6, built to wasm32 cleanly with noopenssl,reqwest,tokioormioin the tree, usinggetrandomwith its wasm feature.Problem. Passkeys need a relying-party implementation that runs in a Worker. The named crate does not. The OIDC crate does, but only through its bring-your-own HTTP client interface, which has to be wired to the harness
HttpClientport.Proposed approach.
webauthn-rsfrom itsmainbranch (0.6 pre-release) and report whether the OpenSSL dependency is gone or made optional; if it builds to wasm32 and its API is stable enough, pin the git revision and record the risk.webauthn-rs-protofor the wire types,ciboriumorcosetfor CBOR and COSE keys,p256,rsaanded25519-dalekfor signature verification,sha2for the client-data hash. Scope it to the two ceremonies we need with attestation formatnoneaccepted and other formats stored but not verified, which is what consumer relying parties do. Estimate the size; it is expected to be a few hundred lines plus tests against the WebAuthn spec's test vectors.openidconnectto the harnessHttpClientport through itsAsyncHttpClienttrait and prove discovery, token exchange and ID-token verification for Google insidewrangler dev.argon2runs within the Worker CPU budget: measureArgon2idat a few parameter sets inwrangler devand on a deployed staging Worker, since wasm is slower than native and the paid plan's CPU limit is the constraint.Acceptance criteria
spikes/wasm-auththat builds withworker-build --releaseand runs underwrangler devwebauthn-rsmain: builds or not, and whyopenidconnectdiscovery and token exchange working against Google through theHttpClientport inwrangler dev