You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在自有网站实现Windows登录?Web Authentication API是否适用?

调用Windows生物识别/PIN登录的标准JS API方案

是的,存在标准JavaScript API可以实现调用Windows人脸、PIN码或指纹等本地认证机制完成登录,**Web Authentication API(简称WebAuthn)**完全满足你的需求。

核心说明

WebAuthn是W3C与FIDO联盟联合制定的公钥认证标准,Windows通过Windows Hello原生支持FIDO2协议,因此当网站使用WebAuthn发起认证请求时,系统会自动唤起Windows Hello的验证界面,允许用户选择人脸、指纹或PIN完成身份验证,无需输入密码。

关键特性与适配要点

  • 平台认证器支持:通过设置authenticatorAttachment: 'platform',可以指定使用Windows内置的平台认证器(即Windows Hello),而非外部安全密钥。
  • 强制用户验证:设置userVerification: 'required'可确保必须触发生物识别或PIN验证,而非仅依赖设备绑定的无用户交互认证。
  • 跨平台兼容性:除Windows外,WebAuthn还支持Mac Touch ID、Android生物识别等主流平台的本地认证方式,无需额外适配不同系统的API。

基础代码示例

注册(生成用户公钥凭证)

async function registerUser() {
  // 服务器生成的随机挑战值,用于防止重放攻击
  const challenge = Uint8Array.from('server-generated-challenge', c => c.charCodeAt(0));
  
  const publicKeyOptions = {
    challenge,
    rp: { name: '你的网站名称' }, // 依赖方(网站)信息
    user: {
      id: Uint8Array.from('unique-user-id', c => c.charCodeAt(0)), // 用户唯一标识
      name: 'user@yourdomain.com',
      displayName: '用户名'
    },
    pubKeyCredParams: [{ type: 'public-key', alg: -7 }], // 使用ES256加密算法
    authenticatorSelection: {
      authenticatorAttachment: 'platform', // 指定使用Windows Hello等平台认证器
      userVerification: 'required' // 强制用户验证(生物识别/PIN)
    },
    timeout: 60000 // 超时时间(毫秒)
  };

  try {
    const credential = await navigator.credentials.create({ publicKey: publicKeyOptions });
    // 将凭证信息发送到服务器存储,用于后续登录验证
    console.log('注册凭证:', credential);
  } catch (error) {
    console.error('注册失败:', error);
  }
}

登录(验证用户公钥凭证)

async function authenticateUser() {
  // 服务器生成的随机挑战值
  const challenge = Uint8Array.from('login-challenge-string', c => c.charCodeAt(0));
  // 从服务器获取该用户已存储的凭证ID
  const storedCredentialId = Uint8Array.from('saved-credential-id', c => c.charCodeAt(0));

  const publicKeyOptions = {
    challenge,
    allowCredentials: [{
      type: 'public-key',
      id: storedCredentialId
    }],
    userVerification: 'required',
    timeout: 60000
  };

  try {
    const assertion = await navigator.credentials.get({ publicKey: publicKeyOptions });
    // 将断言信息发送到服务器验证,验证通过则完成登录
    console.log('登录断言:', assertion);
  } catch (error) {
    console.error('登录失败:', error);
  }
}

注意事项

  • 网站必须部署在HTTPS环境下(localhost开发环境可例外),WebAuthn仅允许在安全上下文中运行。
  • 整个流程需要服务器端配合:存储用户注册时生成的公钥信息,登录时验证客户端返回的签名断言。
  • 用户设备需开启Windows Hello功能,且已配置人脸、指纹或PIN等验证方式。

内容的提问来源于stack exchange,提问作者Michael Chourdakis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 23:45:41