W3C home > Mailing lists > Public > public-webauthn@w3.org > August 2022

Re: [webauthn] Enforce backup eligibility during assertion (#1791)

From: Firstyear via GitHub <sysbot+gh@w3.org>
Date: Wed, 31 Aug 2022 00:10:13 +0000
To: public-webauthn@w3.org
Message-ID: <issue_comment.created-1232297875-1661904612-sysbot+gh@w3.org>
So reading these points, I think it sounds like we *should* have an explicit step in the spec stating that if BE changes during a credential lifecycle the RP can choose to reject or take other action then? 

-- 
GitHub Notification of comment by Firstyear
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1791#issuecomment-1232297875 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Wednesday, 31 August 2022 00:10:15 UTC

This archive was generated by hypermail 2.4.0 : Wednesday, 31 August 2022 00:10:16 UTC