W3C home > Mailing lists > Public > public-webauthn@w3.org > November 2021

Re: [webauthn] Cross origin and Conditional UI (#1671)

From: =JeffH via GitHub <sysbot+gh@w3.org>
Date: Wed, 03 Nov 2021 19:40:42 +0000
To: public-webauthn@w3.org
Message-ID: <issue_comment.created-959879443-1635968441-sysbot+gh@w3.org>
on 2021-11-03 call:
@ve7jtb brings up a webkit bug# where there is a thread where they are discussing whether to allow get() in cross-origin iframes.

John Pascoe from webkit notes that they are imagining adding another user-visible prompt in this case letting user know that this might be used for trackoing and asking for user consent. this somehow leverages the StorageAccess API ....? ( they are imagining safari would request the StorageAccess api permission on behalf of the caller )
(much discussion ensued...see webauthn minutes for more detail)


GitHub Notification of comment by equalsJeffH
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1671#issuecomment-959879443 using your GitHub account

Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Wednesday, 3 November 2021 19:40:45 UTC

This archive was generated by hypermail 2.4.0 : Tuesday, 5 July 2022 07:26:44 UTC