ruby/rubygems · error · Gem::WebauthnVerificationError

Security device verification failed: Did not receive OTP fro

Error message

Security device verification failed: Did not receive OTP from #{host}.

What it means

Error "Security device verification failed: Did not receive OTP from #{host}." thrown in ruby/rubygems.

Source

Thrown at lib/rubygems/gemcutter_utilities/webauthn_listener.rb:73

        responder = SocketResponder.new(socket)

        unless root_path?(req_uri)
          responder.send(NotFoundResponse.for(host))
          raise Gem::WebauthnVerificationError, "Page at #{req_uri.path} not found."
        end

        case method.upcase
        when "OPTIONS"
          responder.send(NoContentResponse.for(host))
          next # will be GET
        when "GET"
          if otp = parse_otp_from_uri(req_uri)
            responder.send(OkResponse.for(host))
            return otp
          end
          responder.send(BadRequestResponse.for(host))
          raise Gem::WebauthnVerificationError, "Did not receive OTP from #{host}."
        else
          responder.send(MethodNotAllowedResponse.for(host))
          raise Gem::WebauthnVerificationError, "Invalid HTTP method #{method.upcase} received."
        end
      end
    end

    private

    def root_path?(uri)
      uri.path == "/"
    end

    def parse_otp_from_uri(uri)
      query = uri.query
      return unless query && !query.empty?

      query.split("&") do |param|

View on GitHub (pinned to 86cbb817a3)

When it happens

Trigger: Thrown at lib/rubygems/gemcutter_utilities/webauthn_listener.rb:73 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of ruby/rubygems@86cbb817a3 (2026-08-23). Data as JSON: /api/errors/f0b2bde117cae61e. Report an issue: GitHub.