Re: [webauthn] [Superset] Updating credential metadata and requesting deletion of stale credentials (#1967)

> When this delete then fails what does the RP do? Do we delete the credential anyway and then the user has to cleanup in their pwmanager / key manager?

The credentials should always be deleted (or rendered inoperable) on the server side. The way I envision it, deleting the credential on the authenticator is a nice-to-have. If the user tries to use that credential to sign in later, the RP can then and there attempt deleting it again, where the deletion is a lot more likely to succeed.


-- 
GitHub Notification of comment by nsatragno
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1967#issuecomment-1749089498 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Thursday, 5 October 2023 15:03:08 UTC