[webauthn] Closed Pull Request: [Meta] Hard-code HKDF in PRF importCryptoKey

emlun has just closed emlun's pull request 1946 for https://github.com/w3c/webauthn:

== [Meta] Hard-code HKDF in PRF importCryptoKey ==
This would merge into PR #1945.

I'm not sure it's wise to have all that flexibility in the PRF `importKey` invocation. Maybe it's better to hard-code importing an unexportable HKDF key instead; this can in turn be used to derive other keys.


<!--
    This comment and the below content is programmatically generated.
    You may add a comma-separated list of anchors you'd like a
    direct link to below (e.g. #idl-serializers, #idl-sequence):

    Don't remove this comment or modify anything below this line.
    If you don't want a preview generated for this pull request,
    just replace the whole of this comment's content by "no preview"
    and remove what's below.
-->
***
<a href="https://pr-preview.s3.amazonaws.com/w3c/webauthn/pull/1946.html" title="Last updated on Aug 23, 2023, 8:03 PM UTC (b72ecc2)">Preview</a> | <a href="https://pr-preview.s3.amazonaws.com/w3c/webauthn/1946/65b635b...b72ecc2.html" title="Last updated on Aug 23, 2023, 8:03 PM UTC (b72ecc2)">Diff</a>

See https://github.com/w3c/webauthn/pull/1946


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 6 September 2023 20:01:06 UTC