Re: [webauthn] residentKey: "preferred-if-unlimited"? (#1822)

> My proposal several months ago was to have platforms map prefered to false for security keys with less than some number of available RK slots.
> 
> For older keys without the ctap2.1 member the platform would always map prefered to false.
> 
> That would let RP always ask for preferred and more or less the correct thing would happen.
> 
> People didn't like that idea at the time.

I think we may need to change it then, since we may encounter issues. 

> 
> RP like Microsoft that only support the discoverable flow would ask for required and the correct thing would happen for them.
> 
> How many RP are going to support alternatives to the autofill UI.
> 

This assumes autofill is the default. The default should be "passwordless" and autofill is a bonus if it's available - especially since it is *not* always available. 



-- 
GitHub Notification of comment by Firstyear
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1822#issuecomment-1370389584 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 4 January 2023 01:25:04 UTC