Re: [webauthn] fix #403: user handle - account relationship

Ok, I'm fine with punting my remaining comments to L2. I'll close #1053.

>RP may wish to allow users to create multiple credentials on the same authnr (a platform authnr, say) that map to the same RP user account

I really can't see how that would ever be useful - it would be like having two identical keys on the same keyring. If you're imagining, say, multiple users on the same laptop, then I'd say it's rather up to the OS to model separate OS accounts/fingerprints/whatever as different sub-authenticators (so that the "one key per (rpId, userHandle, authenticator)" rule still holds)... but I'll concede I might be arguing about irrelevant semantics here.

Anyway, please go ahead as you suggested. :)

-- 
GitHub Notification of comment by emlun
Please view or discuss this issue at https://github.com/w3c/webauthn/pull/1052#issuecomment-420813535 using your GitHub account

Received on Wednesday, 12 September 2018 22:05:46 UTC