You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Webauthn对接Windows Hello时authenticatorSelection参数不生效问题

WebAuthn 平台认证器唤起失败解决方案

问题原因

你遇到的报错已经明确指向缺失的配置项:authenticatorSelection 配置块中没有显式声明 userVerification 参数。Windows Hello 作为 Windows 平台内置的平台级认证器,对该参数的校验比跨平台认证器更严格,Chrome 内核浏览器在该参数未手动配置时默认取值为 preferred,会触发校验拦截,导致无法唤起 Windows Hello 弹窗。

修复后的配置示例

你只需在 authenticatorSelection 中补充 userVerification 字段即可,参考修改后的代码:

challenge: challenge,
rp: {
    name: "Example CORP",
    id  : "localhost"
},
user: {
    id: new Uint8Array(16),
    name: "jdoe@example.com",
    displayName: "John Doe"
},
pubKeyCredParams: [
    {
    type: "public-key",
    alg: -7
    }
],
authenticatorSelection: {
    authenticatorAttachment: "platform",
    // 新增以下配置,无特殊需求优先设置为discouraged
    userVerification: "discouraged"
},
timeout: 60000
};
const credential = navigator.credentials.create({
    publicKey: publicKey 
});

参数说明

userVerification 可选值对应效果如下:

  • discouraged:不强制要求用户完成验证(如PIN、人脸识别、指纹识别),适配绝大多数普通业务场景,配置后即可正常唤起Windows Hello弹窗
  • preferred:浏览器默认值,优先要求验证、无验证能力则跳过,当前Chrome版本对平台认证器使用该默认值会触发校验拦截
  • required:必须完成用户验证才能继续认证流程,适合对安全性要求极高的业务场景

额外校验点

如果补充配置后仍无法正常唤起,可检查以下两项基础配置:

  • 本地开发使用 localhost 域名符合WebAuthn安全要求,线上环境需确保页面运行在HTTPS协议下
  • 确认当前Windows 10系统已经完成Windows Hello的初始配置,功能处于可用状态

内容的提问来源于stack exchange,提问作者Siva Natarajan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.29 19:06:03