Re: [webauthn] residentKey: "preferred-if-unlimited"? (#1822)

This is all one big flow tho and doesn't really involve the rk knowing whether a given credential is resident or not via credprops.

The rp doesn't need (nor really can) offer a flow selected based on the presence of remote creds in the account.

Your last 2 sentences are literally the same as what i mentioned.

If you have an rk you get to autofill and if not you enter your username normally. The rk doesnt need to know about residence or non-residence of credentials (which as we know can change, and iirc at least on the authenticators i know and/or tried, the credential id still works after throwing out the rk from the device or restoring from backup (documented for the trezor t iirc))

-- 
GitHub Notification of comment by My1
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1822#issuecomment-1379693457 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Thursday, 12 January 2023 01:27:14 UTC