eb3362c81ca7288cf0f29791f02909133537a13c
Lands plan tasks 2.10 (pam_u2f line format parser via CredEntry::from_line/ to_line, credId extraction), 2.11 (CredentialsStore add/remove/list with idempotent add-by-credId), and 2.12 (CredsPathResolver dispatching central vs per-user paths). Bundled because the three pieces compose into one storage boundary. CredEntry treats post-username chunks as opaque blobs split on ':', preserving pam_u2f's full record on round-trip. credId = first comma-separated field of a blob. add() is idempotent on credId match (Phase 3 may decide to refresh publicKey on re-enroll; out of scope here). Path resolution: Central -> Storage.central_path verbatim. PerUser -> getpwnam via nix, with a /home/<user>/... fallback if NSS errors (CI users, distro quirks); pam_u2f does the real lookup at auth time, so the fallback only matters for write-on-enroll where the user does exist. 7 tests added; clippy + fmt clean.
authforge
Turnkey U2F / FIDO2 passkey / TOTP MFA for Linux desktops. v1 ships on Ubuntu LTS + GNOME; Debian and KDE Plasma are on the roadmap.
Install (end users)
sudo add-apt-repository ppa:dangerousthings/authforge
sudo apt install authforge
Build from source
See docs/BUILDING.md.
Status
Pre-alpha. Phases 0–1 code complete (workspace scaffold + D-Bus daemon stubs); Phase 2 (storage layer) is next. See docs/plans/ for design, roadmap, and per-phase implementation plans.
Copyright 2026 Dangerous Things, LLC. Licensed under the Apache License, Version 2.0.
Description
Languages
Rust
95.9%
C
3.6%
Jinja
0.3%
Makefile
0.2%