============================================================================== Bootstrapping - registering a passkey requires an existing authenticated session ============================================================================== === Asking for registration options with nobody logged in === $ POST /webauthn/register/options (anonymous) HTTP 400 (empty body) === A one-time token for a username that does not exist === POST /ott/generate -> HTTP 302, Location: http://localhost:8080/login/ott a token was still generated and delivered: d75e51fe-cbde-4add-8d70-231fc6ca490f the response is byte-for-byte what a real username produces - no enumeration oracle POST /login/ott -> HTTP 302, Location: http://localhost:8080/login?error (the failure lands here instead)