Re: [webauthn] reconciling origin and RP ID handling

@AngeloKai said:
> I am just hoping someone can explain to me why an RP should allow credential to be relaxed to a registerable domain suffix?

please see #241 "enforce strict same-origin policy on rpid" and your comment on it before we closed it: https://github.com/w3c/webauthn/issues/241#issuecomment-264337464

see also: https://github.com/w3c/webauthn/pull/464#issuecomment-303785687

-- 
GitHub Notification of comment by equalsJeffH
Please view or discuss this issue at https://github.com/w3c/webauthn/pull/464#issuecomment-304404229 using your GitHub account

Received on Friday, 26 May 2017 22:55:12 UTC