Re: [webauthn] #getAssertion alg needs to pass authenticator selection requirements to authenticatorGetAssertion operation

What we are discussing is platform semantics when calling authenticators. Authenticators are still free to send "uv" bit even if platform has not asked for it (for example, in case of face/fingerprint authenticators). `Forbidden` is a very strong word and gives a sense that authenticators are not allowed to set it. I like `NotRequired` better.



-- 
GitHub Notification of comment by akshayku
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/644#issuecomment-339742915 using your GitHub account

Received on Thursday, 26 October 2017 17:40:17 UTC