W3C home > Mailing lists > Public > public-webauthn@w3.org > December 2021

[webauthn] new commits pushed by agl

From: Adam Langley via GitHub <sysbot+gh@w3.org>
Date: Wed, 15 Dec 2021 20:06:19 +0000
To: public-webauthn@w3.org
Message-ID: <push-1ed258fc0f27efe39f0d548c60a9eb6dcf9fa374-1639598777-sysbot+gh@w3.org>

The following commits were just pushed by agl to https://github.com/w3c/webauthn:

* Tighten requirements for rejecting duplicate credential IDs.

The existing wording suggests rejecting registrations with duplicate
credential IDs, but says that sites may replace the record if they wish.
But accidential duplicate credential IDs aren't worth worrying about and
it's safer to always reject duplicates.

Include a note with the reasoning so that sites who don't want to do
this check can at least think about the implications.

Fixes #1679
  by Adam Langley

* Apply Jeff's suggestion

Co-authored-by: Lucas Garron <code@garron.net>
  by Adam Langley

* Address Lucas and Emil's comments
  by Adam Langley

* Apply Jeff's change

Co-authored-by: =JeffH <jdhodges@google.com>
  by Adam Langley

* Apply Jeff's change

Co-authored-by: =JeffH <jdhodges@google.com>
  by Adam Langley

* Merge pull request #1680 from agl/noselfsign

Tighten requirements for rejecting duplicate credential IDs.
  by Adam Langley

Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Wednesday, 15 December 2021 20:06:21 UTC

This archive was generated by hypermail 2.4.0 : Tuesday, 5 July 2022 07:26:45 UTC