Re: [webauthn] Consider empty allowLists

That sounds roughly right. Would it help to explicitly distinguish credentials that can be generated with just the RP ID vs credentials that can't be generated without the RP providing the credential's ID?

-- 
GitHub Notification of comment by jyasskin
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/387#issuecomment-294058725 using your GitHub account

Received on Friday, 14 April 2017 00:55:58 UTC