Re: [webauthn] Prohibit Create Credential from cross-origin iframes (#1336)

> There might be cause to prohibit resident credential creation from within cross-origin iframes but we’re concerned that we don’t fully understand the legitimate use cases well enough to have a firm opinion on this.

Prohibiting credential creation from within cross-origin iframes may limit or prevent "just in time" registration flows that reduce onboarding friction.

-- 
GitHub Notification of comment by dlongley
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1336#issuecomment-572260833 using your GitHub account

Received on Wednesday, 8 January 2020 21:17:30 UTC