A gate method that releases a file only to a requester who authenticated at a high assurance level with a hardware credential.

Option A — PIV/CAC smart card (HSPD-12, FIPS 201; NIST SP 800-63 AAL3), brokered through an OIDC IdP or an mTLS-terminating edge proxy.
Option B — FIDO2/WebAuthn (e.g. a YubiKey): release only after a phishing-resistant WebAuthn assertion.

Partly shipped: the file_gate_assurance submodule verifies an OIDC IdP assertion (JWKS-pinned signature, iss/aud/exp/acr checks, optional RFC 9449 DPoP and RFC 7662 introspection) and supports an edge-mTLS client-certificate mode. That covers Option A when the credential is brokered through an OIDC IdP. Native WebAuthn verification inside Drupal (Option B) remains open.

Primary development happens on GitHub: https://github.com/Wilkes-Liberty/file_gate/issues/6

Comments

jmcerda created an issue. See original summary.

jmcerda’s picture

GitHub dual-venue implementation record (this issue was never kept open on GitHub after #6 closed as shipped):

https://github.com/Wilkes-Liberty/file_gate/issues/33

That issue tracks remaining work: seamless federated redeem path, optional native WebAuthn (Option B), and deferred A2/step-up items. GitHub #6 remains the historical design/ship record for file_gate_assurance.

jmcerda’s picture

Product decisions locked and Phase A implementation opened:

- Federated path first, native WebAuthn later.
- Audience: federal + commercial FIDO.
- Plain-link primary path via session bridge after OIDC step-up.

GitHub implementation: https://github.com/Wilkes-Liberty/file_gate/issues/33
PR: https://github.com/Wilkes-Liberty/file_gate/pull/34

Docs: docs/assurance-redeem.md on the PR branch.

jmcerda’s picture

Version: 1.0.x-dev » 1.x-dev

Shipped in 1.3.0.

https://www.drupal.org/project/file_gate/releases/1.3.0

- Plain-link primary path: OIDC step-up + FG_AB session bridge (#34)
- Native WebAuthn RP mode: verify_at webauthn + same bridge (#35)

GitHub: https://github.com/Wilkes-Liberty/file_gate/issues/33

jmcerda’s picture

Status: Active » Fixed

Fixed in 1.3.0.

https://www.drupal.org/project/file_gate/releases/1.3.0

- Plain-link primary path: OIDC step-up + FG_AB session bridge
- Native WebAuthn RP mode: verify_at webauthn + same bridge

GitHub: https://github.com/Wilkes-Liberty/file_gate/issues/33

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

jmcerda’s picture

Status: Fixed » Closed (fixed)
jmcerda’s picture

Closed (fixed): phishing-resistant / hardware-backed gate path (plain-link OIDC step-up + native WebAuthn RP) shipped in 1.3.0 (GH #33).

https://www.drupal.org/project/file_gate/releases/1.3.0
https://github.com/Wilkes-Liberty/file_gate/releases/tag/1.3.0

jmcerda’s picture

Confirm Closed (fixed). Work shipped; removing from Open queue.