Re: [webauthn] Inconsistent RP directions for handling credential transports (#1587)

I suspect we should tighten up language by speaking instead terms of credential descriptors, which contain a credential ID  (which is authoritative from the authenticator as part of the attested data on create) and transports (which is advisory and shared unprotected from the client). 

A client SHOULD persist a credential descriptor, with both id and transports, to provide hints to the client for authenticator management and for any future authentication attempts of non-discoverable credentials. Changing or removing values from the transports may impact user experience or even prevent use of the credential.

GitHub Notification of comment by dwaite
Please view or discuss this issue at using your GitHub account

Sent via github-notify-ml as configured in

Received on Tuesday, 23 March 2021 08:48:56 UTC