Re: [webauthn] Should an RP be able to provide finer grained authenticator filtering in attestation options? (#1688)

on 23-Feb-2022 call: 
@sbweeden's position is that enterprise RPs wish to be able to establish their needs up-front when doing makeCred(), rather than after-the-fact (eg by examining resulting cred flags and/or attestation).
@ve7jtb  seems that there would be a number of potential issues/special-cases in trying to broadly address this
@agl notes that giving RPs more tools to discriminate amongst authnrs will lead to situation we are trying to avoid where users have a plethora of authnrs and one or some work with one or some RPs....  though perhaps putting this sort of feature behind an "enterprise policy" is something to consider....



-- 
GitHub Notification of comment by equalsJeffH
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1688#issuecomment-1049203784 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 23 February 2022 20:49:44 UTC