Re: [webauthn] Consider empty allowLists

Right, this was the intention. @jyasskin, the distinction you mention is what #378 was trying to capture - that PR is providing a way for an RP to telegraph that they will be calling getAssertion with an empty allowList, so the client should only create a credential that would be usable in this way.

-- 
GitHub Notification of comment by vijaybh
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/387#issuecomment-294176048 using your GitHub account

Received on Friday, 14 April 2017 15:38:49 UTC