Skip to content

Phase C — Account recovery for passkey-only users, plus parked program items #112

Description

@yahyafakhroji

Sub-issue of datum-cloud/enhancements#738. Phase C of the passkey program.

Scope

Answer "what happens when all passkeys are lost" without falling back to passwords, and
hold the items the team deliberately parked. The recovery design must be signed off
before Phase B GA; the implementation can follow.

What's included

Recovery

  • C1 — Recovery design sign-off. Email-OTP to a short-lived privileged session whose only permitted action is enrolling a new passkey; admin-sent registration link as backstop; recovery codes deferred. Required before Phase B GA.
  • C2 — Interim recovery ships with Phase B: email-OTP login as a permanent fallback. This alone removes the passkey-only lockout class.
  • C3 — Dedicated recovery flow + emails/user-account-recovery.tsx.

Parked — need a team decision

  • True usernameless sign-in (resolving a random credential ID to a user) — blocked on Zitadel #8899. The hint-based fast path shipped in Phase A; this is the remaining capability.
  • Org-level auth policy (require passkey/MFA per org)
  • Adoption and health dashboards (method mix, enrollment funnel, ceremony failure rate)
  • Bot-protection tooling choice — decision deadline: before Phase B GA. Placement fixed: signup and recovery forms only.
  • Playwright virtual-authenticator E2E
  • Passkey last-used timestamps (created-at shipped in Phase A)

Status

Not started. C1 needs scheduling — it blocks Phase B GA, not Phase B start.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions