Re: [webauthn] "credential ID" not signed over by authenticatorGetAssertion operation

a piece of this puzzle is also that in CTAP, the credential ID returned by authenticatorGetAssertion() is optional if allowList has exactly one member -- see #472 

-- 
GitHub Notification of comment by equalsJeffH
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/394#issuecomment-304046351 using your GitHub account

Received on Thursday, 25 May 2017 15:53:18 UTC