W3C home > Mailing lists > Public > public-webauthn@w3.org > August 2022

Re: [webauthn] Enforce backup eligibility during assertion (#1791)

From: Emil Lundberg via GitHub <sysbot+gh@w3.org>
Date: Tue, 30 Aug 2022 15:33:36 +0000
To: public-webauthn@w3.org
Message-ID: <issue_comment.created-1231832126-1661873614-sysbot+gh@w3.org>
> It cannot change after registration. We already have normative text about this: [...]

Yes, but there is no guidance (normative or informative) on what RPs should do if they encounter the forbidden cases (`BE=1 => 0` or `BE=0, BS=1`).

-- 
GitHub Notification of comment by emlun
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1791#issuecomment-1231832126 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Tuesday, 30 August 2022 15:33:42 UTC

This archive was generated by hypermail 2.4.0 : Tuesday, 30 August 2022 15:33:44 UTC