Skip to content

Infer passkey display name from AAGUID - #65343

Merged
MackinnonBuck merged 7 commits into
mainfrom
mbuck/infer-passkey-display-name
Feb 11, 2026
Merged

MackinnonBuck merged 7 commits into
mainfrom
mbuck/infer-passkey-display-name

Conversation

@MackinnonBuck

Copy link
Copy Markdown
Member

Infer passkey display name from AAGUID

Summary

This PR improves the passkey user experience in the Blazor Web App project template by automatically inferring display names for passkeys based on their AAGUID (Authenticator Attestation GUID).

Fixes #63630

Changes

Framework (Microsoft.AspNetCore.Identity)

  • Added Aaguid property (byte[]?) to UserPasskeyInfo and IdentityPasskeyData to persist the authenticator's AAGUID
  • Updated PasskeyHandler to extract the AAGUID during passkey attestation
  • Updated EF Core mappings to include the new property (no schema migration required since IdentityPasskeyData uses a JSON column)

Blazor Web App Template

  • Added PasskeyAuthenticators.cs which maps known AAGUIDs to friendly authenticator names
  • Updated Passkeys.razor to display inferred names and creation dates for each passkey
  • For known authenticators, the name is automatically assigned without prompting the user
  • For unknown authenticators, the user is still redirected to the rename page

Supported Authenticators

The template includes mappings for the top 5 most commonly used passkey authenticators:

  • Google Password Manager
  • iCloud Keychain
  • Windows Hello
  • 1Password
  • Bitwarden

Developers can easily add more authenticators by extending the dictionary in PasskeyAuthenticators.cs.

Demo

Before

passkey_ui_old.mp4

After

passkey_ui_new.mp4

Copilot AI review requested due to automatic review settings February 6, 2026 00:10
@github-actions github-actions Bot added the area-identity Includes: Identity and providers label Feb 6, 2026
@MackinnonBuck
MackinnonBuck requested review from halter73 and javiercn and removed request for Copilot February 6, 2026 00:11
Copilot AI review requested due to automatic review settings February 6, 2026 18:09

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR enhances passkey UX by persisting the authenticator AAGUID during attestation and using it in the Blazor Web App template to infer a friendly default passkey display name (reducing the need for a rename prompt).

Changes:

  • Add Aaguid (byte[]?) to UserPasskeyInfo and IdentityPasskeyData, and extract it during passkey attestation.
  • Update store/test mappings and spec assertions to round-trip the new Aaguid field.
  • Add template logic to map known AAGUIDs to friendly authenticator names and display inferred names + creation date in the passkeys list.

Reviewed changes

Copilot reviewed 13 out of 13 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
src/ProjectTemplates/Web.ProjectTemplates/content/BlazorWeb-CSharp/BlazorWebCSharp.1/Components/Account/PasskeyAuthenticators.cs Adds AAGUID→friendly-name mapping and helper methods for display/inference.
src/ProjectTemplates/Web.ProjectTemplates/content/BlazorWeb-CSharp/BlazorWebCSharp.1/Components/Account/Pages/Manage/Passkeys.razor Uses inferred display names and creation dates; auto-assigns a name for known authenticators.
src/Identity/test/Shared/PocoModel/PocoUserPasskey.cs Extends test POCO model with an AAGUID field.
src/Identity/test/InMemory.Test/InMemoryStore.cs Maps AAGUID between POCO and UserPasskeyInfo.
src/Identity/samples/IdentitySample.PasskeyUI/InMemoryUserStore.cs Maps AAGUID between POCO and UserPasskeyInfo in sample store.
src/Identity/samples/IdentitySample.PasskeyConformance/InMemoryUserStore.cs Same as above for conformance sample store.
src/Identity/Specification.Tests/src/IdentitySpecificationTestBase.cs Adds AAGUID to passkey equality assertions.
src/Identity/Extensions.Stores/src/PublicAPI.Unshipped.txt Declares new public API surface for IdentityPasskeyData.Aaguid.
src/Identity/Extensions.Stores/src/IdentityPasskeyData.cs Adds persisted Aaguid property.
src/Identity/Extensions.Core/src/UserPasskeyInfo.cs Adds Aaguid property to passkey model.
src/Identity/Extensions.Core/src/PublicAPI.Unshipped.txt Declares new public API surface for UserPasskeyInfo.Aaguid.
src/Identity/EntityFrameworkCore/src/IdentityUserPasskeyExtensions.cs Maps Aaguid between EF entity JSON payload and UserPasskeyInfo.
src/Identity/Core/src/PasskeyHandler.cs Extracts AAGUID from attestation and sets it on the created UserPasskeyInfo.

Comment thread src/Identity/EntityFrameworkCore/src/IdentityUserPasskeyExtensions.cs Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-identity Includes: Identity and providers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Implement better passkey display name inference

3 participants