Re: [webauthn] Relying Party Session

No, the specification does not say anything about that. The [Relying Party Operations][rp-ops] attempt to describe what the RP needs to do to correctly identify the user to be authenticated, but that's about it.

Yes, that seems like a valid implementation approach.

[rp-ops]: https://w3c.github.io/webauthn/#rp-operations

-- 
GitHub Notification of comment by emlun
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1111#issuecomment-437845218 using your GitHub account

Received on Monday, 12 November 2018 11:22:39 UTC