Re: [webauthn] Missing specification on rpId validations when calling credentials.get() from a different origin (#1731)

On 2022-05-18 WG call: we should also point out that RPs need to make sure their subdomains are sufficiently secured too. For example, if users can run arbitrary script on a subdomain of the RP ID, then user-submitted code could hijack authentications for the parent domain.

-- 
GitHub Notification of comment by emlun
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1731#issuecomment-1130471093 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 18 May 2022 19:49:44 UTC