Re: [webauthn] Explicitly prohibit use of WebAuthn from non-visible cross-origin iframes (#1303)

As an update, I'm still gathering feedback internally per @agl's comment above. Since there's feeling that this PR would not be welcome, I haven't finished shaping the language I was using until I get our internal temperature.

-- 
GitHub Notification of comment by jcjones
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1303#issuecomment-542845818 using your GitHub account

Received on Wednesday, 16 October 2019 19:02:27 UTC