Re: [webauthn] fix #403: user handle - account relationship

I'd proposed:

>Given our short timeframe for PropRec, perhaps we can just delete the Note from this PR, not do PR #1053 (for now), and merge the remainder of the clarification of the user handle definition (as it presently is),

@emlun replied:
> please go ahead as you suggested. :)

Ok, thx, will do.

> If you're imagining, say, multiple users on the same laptop, then I'd say it's rather up to the OS to model separate OS accounts/fingerprints/whatever as different sub-authenticators (so that the "one key per (rpId, userHandle, authenticator)" rule still holds)

yeah, that's another aspect of these subtleties it seems. 

-- 
GitHub Notification of comment by equalsJeffH
Please view or discuss this issue at https://github.com/w3c/webauthn/pull/1052#issuecomment-422214929 using your GitHub account

Received on Tuesday, 18 September 2018 00:35:48 UTC