Re: [webauthn] Add notion of forbidding resident credential creation (#1149)

I'm not sure that there is a case where the RP requires forbidden behavior explicitly. But the thing is that RP should have information whether the key is located in the client or not. With that information, RP may provides authentication user flow.

-- 
GitHub Notification of comment by Kieun
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1149#issuecomment-459368558 using your GitHub account

Received on Thursday, 31 January 2019 14:41:50 UTC