[webauthn] Merged Pull Request: Adding flexibility in client origin scheme validation to align with real world implementations

nicksteele has just merged abergs's pull request 2018 for https://github.com/w3c/webauthn:

== Adding flexibility in client origin scheme validation to align with real world implementations ==
I suggest adding a little bit of flexibility to the requirements on validating the scheme to be `https`. This is in response to the real world implementation by clients, where clients (browsers, chrome) allow webauthn on `localhost` running on the `http`-scheme. We've been receiving negative feedback for following this part of the spec. I wanted to suggest adding just a little bit of flexibility here, hopefully without opening a can of DNS worms. 


I might be sticking my shin out here, since I know the topic of localhost has been brought up in previous calls with varying (dis)-agreement. E.g issue #1204 morphed into a discussion on DNS. 

Either I'm misinterpreting the current writing, but to me it's quite clear about not allowing `http` in any case. 

Original:
![CleanShot 2024-01-29 at 10 31 55](https://github.com/w3c/webauthn/assets/357283/8446eaa4-2303-4030-a7cf-306b74387c48)

Updated:
![image](https://github.com/w3c/webauthn/assets/357283/c0200116-f896-4f11-b78b-511bf0deb5c5)


<!--
    This comment and the below content is programmatically generated.
    You may add a comma-separated list of anchors you'd like a
    direct link to below (e.g. #idl-serializers, #idl-sequence):

    Don't remove this comment or modify anything below this line.
    If you don't want a preview generated for this pull request,
    just replace the whole of this comment's content by "no preview"
    and remove what's below.
-->
***
<a href="https://pr-preview.s3.amazonaws.com/abergs/webauthn/pull/2018.html" title="Last updated on Feb 21, 2024, 5:57 PM UTC (9f8fa53)">Preview</a> | <a href="https://pr-preview.s3.amazonaws.com/w3c/webauthn/2018/73b3562...abergs:9f8fa53.html" title="Last updated on Feb 21, 2024, 5:57 PM UTC (9f8fa53)">Diff</a>

See https://github.com/w3c/webauthn/pull/2018


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 21 February 2024 20:24:03 UTC