Re: [webauthn] Redirected Icon Validation (#1139)

We do not currently process icons, so have no applicable behaviour here. However, if we did, I don't think that we would be comfortable fetching the icon when displaying the account chooser because that would disclose to the network and server that a given account was displayed. So we would likely try to fetch and cache the icon at registration time, perhaps turning it into a `data` URL. Likewise, we would not look kindly on a redirect to HTTP.

-- 
GitHub Notification of comment by agl
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1139#issuecomment-455320098 using your GitHub account

Received on Thursday, 17 January 2019 20:27:12 UTC