Re: [webauthn] Prohibit Create Credential from cross-origin iframes (#1336)

> @jcjones wrote:
> 
> > I would like to propose that we specify WebAuthn's Create Credential operation be only callable from the top-level context.
> 
> Do you actually mean to say "...only callable from browsing contexts that are top-level or [same-origin with their ancestors](https://www.w3.org/TR/credential-management-1/#same-origin-with-its-ancestors)" ?

Oops, Yes, I apologize for my lack of rigor there -- I'll edit to be clearer.

-- 
GitHub Notification of comment by jcjones
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1336#issuecomment-548895117 using your GitHub account

Received on Friday, 1 November 2019 18:14:35 UTC