Re: [webauthn] Cross-origin credential creation in iframes (#1656)

> Allow a site in a full page redirect to create a non-discoverable credential for a third site.

That's not what is being proposed here, is it? Only RP should be able to create a credential for itself. The proposal is for the RP to be in an iframe instead of top-level context. Sorry if I'm not understanding the "third site" comment.

-- 
GitHub Notification of comment by rsolomakhin
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1656#issuecomment-891099947 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Monday, 2 August 2021 15:04:06 UTC