W3C home > Mailing lists > Public > public-webauthn@w3.org > January 2022

Re: [webauthn] Incorrect "to create" phrase used in get() section's introduction? (#1687)

From: =JeffH via GitHub <sysbot+gh@w3.org>
Date: Mon, 10 Jan 2022 19:31:11 +0000
To: public-webauthn@w3.org
Message-ID: <issue_comment.created-1009272465-1641843069-sysbot+gh@w3.org>
Well, to perhaps better explain why I'm thinking the "to create" phrase is (possibly) incorrect in the quoted paragraph...

[Those quoted paragraphs above](https://github.com/w3c/webauthn/issues/1687#issue-1077103548) are in the section about using an existing credential to make an assertion -- they are not discussing credential creation. And the first quoted paragraph says:
> The **get()** implementation ... calls PublicKeyCredential.[[CollectFromCredentialStore]]() to **_collect_ any credentials that should be available _without user mediation_**

..and then the second paragraph is explaining why the webauthn spec simply "...inherits the default behavior of Credential.[[CollectFromCredentialStore]](), of returning an empty set.", and it would seem that the reason ought to be that it is because webauthn requires a gesture (ie user mediation) _to use_ any credentials (rather than "to create").



-- 
GitHub Notification of comment by equalsJeffH
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1687#issuecomment-1009272465 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Monday, 10 January 2022 19:31:12 UTC

This archive was generated by hypermail 2.4.0 : Thursday, 24 March 2022 20:38:44 UTC