Re: [webauthn] AppID / origin

[Section 5.5 PublicKeyCredentialRequestOptions](https://w3c.github.io/webauthn/#dictdef-publickeycredentialrequestoptions) allows an application to pass in a claimed `rpId` parameter to a `.get()` call. My question was whether the AppID extension should be using the claimed (and validated) `rpId` as the facet or the `origin`. Although after thinking about this more, that doesn't really make sense...

-- 
GitHub Notification of comment by apowers313
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/853#issuecomment-377037430 using your GitHub account

Received on Wednesday, 28 March 2018 21:09:09 UTC