Re: [webauthn] residentKey: "preferred-if-unlimited"? (#1822)

> We introduced preferred in Level2 because Google and some others thought it would be good for some RP to begin making discoverable credentials in preparation for going passwordless

but you dont need RKs for passwordless at all. RKs are needed for usernameless (which is also nice but far less important than passwordless)

> These sites will use the autofill UI or a button with no allow list. These sites must logically set resident key to required or they won't work.

true that obviously needs them, when you dont want the user to need to enter a username.

-- 
GitHub Notification of comment by My1
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1822#issuecomment-1310200303 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Thursday, 10 November 2022 12:19:02 UTC