Re: [webauthn] residentKey: "preferred-if-unlimited"? (#1822)

I think it would be good to agree on the fact that a passkey needs to be a discoverable credential, so `rk: required` in any situation where the credential to be created is called a passkey. 

RPs can still give users the option to "Add a security key" in the user profile with different parameters (e.g., `attachment: cross-platform`, `rk: preferred`), resulting in a credential that must be used in different flows than passkeys, i.e. always requiring a username first.

-- 
GitHub Notification of comment by FlxMgdnz
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1822#issuecomment-1378394948 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 11 January 2023 08:28:52 UTC