Re: [webauthn] Cross origin and Conditional UI (#1671)

on 2021-11-03 call:
@ve7jtb brings up a webkit bug# where there is a thread where they are discussing whether to allow get() in cross-origin iframes.

John Pascoe from webkit notes that they are imagining adding another user-visible prompt in this case letting user know that this might be used for trackoing and asking for user consent. this somehow leverages the StorageAccess API ....? ( they are imagining safari would request the StorageAccess api permission on behalf of the caller )
(much discussion ensued...see webauthn minutes for more detail)


 
 


-- 
GitHub Notification of comment by equalsJeffH
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1671#issuecomment-959879443 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 3 November 2021 19:40:45 UTC