Re: [webauthn] web-api: is further language needed describing AppID (aka rpId) usage ?

my comment on PR #83 that we are punting over to here..

I am nominally fine with merging these commits to master given that 
this is a working draft and nothing is cast in stone as yet.

I am somewhat concerned that we are diluting the 
description/definition of the RP ID approach in terms of how it also 
applies to native platform APIs and is a cohesive approach which does 
not obviate the Web Same Origin Policy and does not supplant federated
 identity approaches. I argue that we (where "we" is some superset 
containing interested W3C WebAuthn WG participants) need to determine 
where this overall "RP ID and facet denotation" approach is 
defined/published (it seems there are nominally valid arguments that 
the W3C is not the applicable place), and do so, at least as a 
explanatory document.


-- 
GitHub Notification of comment by equalsJeffH
Please view or discuss this issue at 
https://github.com/w3c/webauthn/issues/8#issuecomment-221100127 using 
your GitHub account

Received on Monday, 23 May 2016 21:21:39 UTC