Locked out of a Discourse forum due to passkey bug?

I’m a member of https://www.trucknetuk.com/ which uses Discourse 3.5.0.beta3-dev.

I opted in to use my Thetis Pro passkey device, which worked fine until I had to re-install Windows. I’m now getting “This security key doesn’t look familiar”. I found that if I took the key before attempting login, then re-inserted when prompted, I got the following:

“An error occurred: A security key with the provided credential ID could not be found”.

I can see that the key for the site exists in Thetis Pro Key Manager app.

Note: I’ve tried it via Chrome, Firefox, mobile etc, as well as my laptop, with the same resulting message. And all other keys on the device work fine for other sites.

I tried contacting the site owner who just told me to do a password reset - not sure he understands passkeys! Yes, I can do a password reset, but it still needs passkeys to complete.

I also created a new account and a thread at Locked out as Passkeys seems broke and no backup / recovery options offered - FEEDBACK FORUM - Let Us Know! (INTERACTIVE) - Trucknet UK - but not much help there.

So, is there anything else I can do, or ask the forum admin to try, or somehow initiate a fallback? I don’t recall any way of creating a backup passkey using Windows Hello or Google Password Manager, which is what I normally do. Nor is there any other option that a physical key when clicking “cancel”.

Any ideas?! Thanks.

Hey, welcome to meta

I can’t help with why it happens. It’s interesting that it only happens with Discourse.

Have you tried authenticating with a login link? You don’t need a passkey to complete the process.

image

2 Likes

Thanks for getting back to me. Sorry, forgot to mention I tried this before.
I click the link in the email ( www.trucknetuk.com/session/email-login/XXXXXX), but I’m right back to this screen:

If I choose “Authenticate with security key” I get the “doesn’t look familiar” error. If I choose “try another way”, I get a page saying:

When you have your physical security key or compatible mobile device prepared press the Authenticate with Security Key button below.

However, there’s no such box shown, just a textarea to paste something in.

[EDIT] - sorry, due to the “only one image per post for new users” error, I’ll have to split this into another reply…

1 Like

I took a guess and tried pasting both “user ID” and “credential ID” into the box, but in both cases it says:

The provided public key is invalid.

Just to prove I definitely have a valid key for the site, here’s the credential itself on the key:

This is getting intriguing!

(again, sorry for 3 replies, but it was due to “one per post” limit)

1 Like

Hey @digitaltoast welcome! Just responding here that we’ve seen your issue and are discussing…