Re: [webauthn] "Verify" is undefined (#2208)

In this context, this is describing processing logic for the consumer of the API and the received messages. 

A failed verify will defer to the application's error processing logic. It is a runtime security check on the message received via the API, and not a logical invariant.

I suspect an enhancement here would be to describe relying party behavior when a verification step fails across the entire section.

-- 
GitHub Notification of comment by dwaite
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/2208#issuecomment-2489372452 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 20 November 2024 19:22:01 UTC