Re: [webauthn] Fix #720: Don't return user handle in 2nd factor mode

Wait - actually, the response processing server (ResPS) needs to be able to verify that the returned `challenge` equals that sent to the client, so there needs to be some trusted communication path between the request processing server (ReqPS) and the ResPS so the ResPS can obtain the `challenge` from the ReqPS. Could that message then not also contain the user ID (if known, i.e. in 2nd factor mode)?

-- 
GitHub Notification of comment by emlun
Please view or discuss this issue at https://github.com/w3c/webauthn/pull/730#issuecomment-353806589 using your GitHub account

Received on Sunday, 24 December 2017 22:59:23 UTC