Re: [webauthn] Tighten security scope by port

That would work, however, if this isn't feasible for v1 and given all implementations have shipped already, it's not immediately clear to me if this is still worth pursuing.

In https://github.com/whatwg/fetch/issues/687#issuecomment-393185500 not everyone was convinced that such a port restriction would be meaningful either, so maybe we should just give up on that altogether?

-- 
GitHub Notification of comment by annevk
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/873#issuecomment-408070806 using your GitHub account

Received on Thursday, 26 July 2018 11:49:27 UTC