Re: [webauthn] Enforce strict same-origin policy on rpId

see also this new comment 
(https://github.com/w3ctag/spec-reviews/issues/97#issuecomment-257799820)
 on "W3C TAG: Review Web Authentication spec" that is explicitly about
 this issue and the TAG is ok with use of eTLD+1 as it is presently 
specified. 

-- 
GitHub Notification of comment by equalsJeffH
Please view or discuss this issue at 
https://github.com/w3c/webauthn/issues/241#issuecomment-258222180 
using your GitHub account

Received on Thursday, 3 November 2016 17:53:50 UTC