Skip to content

feat(evals): add passkey sign-in evals for Auth0.Android and Auth0.swift - #276

Draft
subhankarmaiti wants to merge 2 commits into
mainfrom
passkeys-mobile-evals
Draft

subhankarmaiti wants to merge 2 commits into
mainfrom
passkeys-mobile-evals

Conversation

@subhankarmaiti

Copy link
Copy Markdown
Contributor

Adds evals covering passkey sign-in for the two mobile SDKs, Auth0.Android and Auth0.swift. Each starts from a working Universal Login app and asks the model to add passwordless passkey login.

The graders check that the solution requests a passkey challenge, drives the platform authenticator (AndroidX CredentialManager / Apple AuthenticationServices) from that challenge, and exchanges the result back through the SDK to obtain and store credentials — including the security-sensitive parts: taking the relying-party id and challenge from the SDK object rather than hardcoding them, letting the credentials manager hold the tokens, and on Android chaining validateClaims() so ID-token validation isn't skipped. L5 also guards against the passkey wrapper classes removed in Auth0.Android v4.

@coderabbitai

coderabbitai Bot commented Sep 7, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant