Re: [webauthn] agl doesn't understand extensions

>4. The instructions say only that the RP should check that the echoed extensions are a subset, but it's unclear if that means that the values must be identical [...]

I read this to mean the extension IDs (the keys of the object) should be a subset of the requested extension IDs, but I agree this could be clearer. I also think the RP ops should probably have an additional step that vaguely specifies the extension output values are "as expected". I can take care of that in #804.

-- 
GitHub Notification of comment by emlun
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/803#issuecomment-366306289 using your GitHub account

Received on Friday, 16 February 2018 17:41:40 UTC