A gate method that releases a file only to a requester who authenticated at a high assurance level with a hardware credential.
Option A — PIV/CAC smart card (HSPD-12, FIPS 201; NIST SP 800-63 AAL3), brokered through an OIDC IdP or an mTLS-terminating edge proxy.
Option B — FIDO2/WebAuthn (e.g. a YubiKey): release only after a phishing-resistant WebAuthn assertion.
Partly shipped: the file_gate_assurance submodule verifies an OIDC IdP assertion (JWKS-pinned signature, iss/aud/exp/acr checks, optional RFC 9449 DPoP and RFC 7662 introspection) and supports an edge-mTLS client-certificate mode. That covers Option A when the credential is brokered through an OIDC IdP. Native WebAuthn verification inside Drupal (Option B) remains open.
Primary development happens on GitHub: https://github.com/Wilkes-Liberty/file_gate/issues/6
Comments
Comment #2
jmcerdaGitHub dual-venue implementation record (this issue was never kept open on GitHub after #6 closed as shipped):
https://github.com/Wilkes-Liberty/file_gate/issues/33
That issue tracks remaining work: seamless federated redeem path, optional native WebAuthn (Option B), and deferred A2/step-up items. GitHub #6 remains the historical design/ship record for file_gate_assurance.
Comment #3
jmcerdaProduct decisions locked and Phase A implementation opened:
- Federated path first, native WebAuthn later.
- Audience: federal + commercial FIDO.
- Plain-link primary path via session bridge after OIDC step-up.
GitHub implementation: https://github.com/Wilkes-Liberty/file_gate/issues/33
PR: https://github.com/Wilkes-Liberty/file_gate/pull/34
Docs: docs/assurance-redeem.md on the PR branch.
Comment #4
jmcerdaShipped in 1.3.0.
https://www.drupal.org/project/file_gate/releases/1.3.0
- Plain-link primary path: OIDC step-up + FG_AB session bridge (#34)
- Native WebAuthn RP mode: verify_at webauthn + same bridge (#35)
GitHub: https://github.com/Wilkes-Liberty/file_gate/issues/33
Comment #5
jmcerdaFixed in 1.3.0.
https://www.drupal.org/project/file_gate/releases/1.3.0
- Plain-link primary path: OIDC step-up + FG_AB session bridge
- Native WebAuthn RP mode: verify_at webauthn + same bridge
GitHub: https://github.com/Wilkes-Liberty/file_gate/issues/33
Comment #7
jmcerdaComment #8
jmcerdaClosed (fixed): phishing-resistant / hardware-backed gate path (plain-link OIDC step-up + native WebAuthn RP) shipped in 1.3.0 (GH #33).
https://www.drupal.org/project/file_gate/releases/1.3.0
https://github.com/Wilkes-Liberty/file_gate/releases/tag/1.3.0
Comment #9
jmcerdaConfirm Closed (fixed). Work shipped; removing from Open queue.