Sadly there are no work arounds :( You can enforce it's only a security key in the registration by forcing attestation and consulting the aaguid with a list of known authenticators, and then throw an error if it's not, but otherwise, there is no way to achieve this. -- GitHub Notification of comment by Firstyear Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1750#issuecomment-1160957032 using your GitHub account -- Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-configReceived on Monday, 20 June 2022 23:39:20 UTC
This archive was generated by hypermail 2.4.0 : Tuesday, 5 July 2022 07:26:46 UTC