You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Karate中为Chrome浏览器WebAuthn添加virtualAuthenticator

使用Karate结合Virtual Authenticator实现WebAuthn Passkey自动化测试(无需实际认证)

核心逻辑

Karate本身没有内置WebAuthn测试能力,但可以通过Chrome DevTools Protocol(CDP)的Virtual Authenticator API,在浏览器中模拟Passkey的注册、认证全流程,全程不需要物理密钥或生物识别操作。

具体实现步骤

  1. 启动带调试端口的浏览器
    先开一个带远程调试功能的Chrome/Edge实例,让Karate能通过CDP和它通信:

    chrome --remote-debugging-port=9222 --user-data-dir=/tmp/karate-webauthn-profile
    
  2. 在Karate中建立CDP连接
    通过Karate的CDP集成模块连接到调试端口:

    * def cdpSession = karate.callSingle('classpath:cdp/connect.feature', { port: 9222 })
    
  3. 创建虚拟认证器实例
    调用CDP的WebAuthn.addVirtualAuthenticator接口,创建支持Passkey的虚拟认证器(关键是开启hasResidentKey):

    * def authConfig = {
        protocol: "ctap2",
        transport: "usb",
        hasResidentKey: true,
        hasUserVerification: false,
        isUserVerified: true
      }
    * def authId = cdpSession.send('WebAuthn.addVirtualAuthenticator', authConfig).authenticatorId
    
  4. 自动处理Passkey流程

    • 注册环节:当页面触发WebAuthn注册请求时,虚拟认证器会自动生成并存储密钥对,完全不需要用户手动操作
    • 认证环节:如果需要跳过用户验证,直接调用WebAuthn.setUserVerified标记认证器已通过验证,就能自动完成凭证断言
  5. 测试后清理资源
    测试结束记得删掉虚拟认证器,避免影响后续测试:

    * cdpSession.send('WebAuthn.removeVirtualAuthenticator', { authenticatorId: authId })
    

踩坑提示

  • 确保用的是Chrome 80+/Edge 80+以上版本,老版本不支持Virtual Authenticator API
  • 调试端口(比如9222)别被其他进程占用,否则连不上
  • 要测多用户场景的话,可以创建多个虚拟认证器实例,用authenticatorId区分各自的凭证

内容的提问来源于stack exchange,提问作者shrik18

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 23:31:07