Weekly github digest (WebAuthn)

Issues
------
* w3c/webauthn (+6/-13/💬37)
  6 issues created:
  - [Editorial] platform authenticator relationship to WebAuthn Client and Client Device (by timcappalli)
    https://github.com/w3c/webauthn/issues/2164 [type:editorial] 
  - Reconciling with FedCM errors (by npm1)
    https://github.com/w3c/webauthn/issues/2158 [type:technical] 
  - Providing AAGUID on Get (by timcappalli)
    https://github.com/w3c/webauthn/issues/2157 [type:technical] 
  - Bit set by the SPC extension should backed up as part of the Public Key Credential Source (by timcappalli)
    https://github.com/w3c/webauthn/issues/2153 [type:technical] 
  - Add `challengeUrl` (by nsatragno)
    https://github.com/w3c/webauthn/issues/2152 [type:technical] 
  - authenticatorDisplayName should use a localizable language map (by timcappalli)
    https://github.com/w3c/webauthn/issues/2151 [type:technical] 

  24 issues received 37 new comments:
  - #2164 [Editorial] platform authenticator relationship to WebAuthn Client and Client Device (2 by emlun)
    https://github.com/w3c/webauthn/issues/2164 [type:editorial] 
  - #2158 Reconciling with FedCM errors (1 by timcappalli)
    https://github.com/w3c/webauthn/issues/2158 [type:technical] 
  - #2157 Providing AAGUID on Get (2 by Kieun, timcappalli)
    https://github.com/w3c/webauthn/issues/2157 [type:technical] 
  - #2156 Add `authenticatorDisplayName` to Step 27 and Step 23 of the registration and authentication ceremonies respectively (2 by emlun, timcappalli)
    https://github.com/w3c/webauthn/issues/2156 [type:editorial] 
  - #2153 Bit set by the SPC extension should backed up as part of the Public Key Credential Source (1 by selfissued)
    https://github.com/w3c/webauthn/issues/2153 [type:technical] 
  - #2152 Add `challengeUrl` (7 by MasterKale, agl, arianvp, emlun, kenrb, nsatragno)
    https://github.com/w3c/webauthn/issues/2152 [type:technical] 
  - #2151 authenticatorDisplayName should use a localizable language map (4 by aphillips, emlun)
    https://github.com/w3c/webauthn/issues/2151 [type:technical] 
  - #2146 Allow `platform`-based self attestation with non-zero AAGUID when `AttestationConveyancePreferenceOption` `"none"` is used (1 by pascoej)
    https://github.com/w3c/webauthn/issues/2146 [type:technical] 
  - #1962 Should credentials requested with attestation=none include an AAGUID? (1 by pascoej)
    https://github.com/w3c/webauthn/issues/1962 [type:technical] [type:editorial] [@Risk] 
  - #1917 Allow desired attestation format to be an ordered list (1 by agl)
    https://github.com/w3c/webauthn/issues/1917 [type:technical] 
  - #1913 Misaligned steps in Section 7.2 (1 by emlun)
    https://github.com/w3c/webauthn/issues/1913 [type:editorial] 
  - #1667 Cross origin authentication without iframes (accommodating SPC in WebAuthn) (1 by akshayku)
    https://github.com/w3c/webauthn/issues/1667 [stat:Discuss] 
  - #1656 Cross-origin credential creation in iframes (1 by agl)
    https://github.com/w3c/webauthn/issues/1656 [type:technical] [@Risk] 
  - #1646 Trailing position of metadata (1 by aphillips)
    https://github.com/w3c/webauthn/issues/1646 [type:technical] [i18n-needs-resolution] [@Risk] 
  - #1645 [Editorial] Truncation description inaccurate (1 by aphillips)
    https://github.com/w3c/webauthn/issues/1645 [type:editorial] [i18n-needs-resolution] [@Risk] 
  - #1644 Mechanism for encoding *direction* metadata may need more work (1 by aphillips)
    https://github.com/w3c/webauthn/issues/1644 [type:technical] [type:editorial] [i18n-needs-resolution] [@Risk] 
  - #1643 Use of in-field metadata not preferred (1 by aphillips)
    https://github.com/w3c/webauthn/issues/1643 [type:technical] [i18n-needs-resolution] [@Risk] 
  - #1642 Unicode "tag" characters are deprecated for language tagging (1 by aphillips)
    https://github.com/w3c/webauthn/issues/1642 [type:technical] [i18n-needs-resolution] [@Risk] 
  - #1641 U+ notation incorrect (1 by aphillips)
    https://github.com/w3c/webauthn/issues/1641 [type:editorial] [i18n-needs-resolution] [@Risk] 
  - #1640 Syncing Platform Keys, Recoverability and Security levels (1 by akshayku)
    https://github.com/w3c/webauthn/issues/1640 [type:technical] [@Risk] 
  - #1567 Surface platform authenticator status in the `create` (and maybe `get`) response / help RPs track UV/PA/RK (1 by emlun)
    https://github.com/w3c/webauthn/issues/1567 [type:technical] 
  - #1554 Adding info about HSTS for the RPID to client Data. (2 by nicksteele)
    https://github.com/w3c/webauthn/issues/1554 [type:technical] 
  - #1449 Requesting properties of created credentials. (1 by timcappalli)
    https://github.com/w3c/webauthn/issues/1449 [type:technical] [subtype:FeatureProposal] [@Risk] 
  - #1291 Minor cleanups from PR 1270 review (1 by emlun)
    https://github.com/w3c/webauthn/issues/1291 [type:editorial] [priority:low] [@Risk] 

  13 issues closed:
  - Misaligned steps in Section 7.2 https://github.com/w3c/webauthn/issues/1913 [type:editorial] 
  - Reconciling with FedCM errors https://github.com/w3c/webauthn/issues/2158 [type:technical] 
  - undefined terms and terms we really ought to define https://github.com/w3c/webauthn/issues/462 [type:editorial] [stat:OnGoing] [@Risk] 
  - Minor cleanups from PR 1270 review https://github.com/w3c/webauthn/issues/1291 [type:editorial] [priority:low] [@Risk] 
  - Requesting properties of created credentials. https://github.com/w3c/webauthn/issues/1449 [type:technical] [subtype:FeatureProposal] [@Risk] 
  - Adding info about HSTS for the RPID to client Data. https://github.com/w3c/webauthn/issues/1554 [type:technical] 
  - Adding info about HSTS for the RPID to client Data. https://github.com/w3c/webauthn/issues/1554 [type:technical] 
  - Cross origin authentication without iframes (accommodating SPC in WebAuthn) https://github.com/w3c/webauthn/issues/1667 [stat:Discuss] 
  - Syncing Platform Keys, Recoverability and Security levels https://github.com/w3c/webauthn/issues/1640 [type:technical] [@Risk] 
  - Possible experiences in a future WebAuthn https://github.com/w3c/webauthn/issues/1637 [type:technical] [@Risk] 
  - Cross-origin credential creation in iframes https://github.com/w3c/webauthn/issues/1656 [type:technical] [@Risk] 
  - Ambiguous instructions in the Android Key Attestation Statement Format verification procedure https://github.com/w3c/webauthn/issues/1980 [type:technical] [@Risk] 
  - Allow desired attestation format to be an ordered list https://github.com/w3c/webauthn/issues/1917 [type:technical] 



Pull requests
-------------
* w3c/webauthn (+5/-0/💬8)
  5 pull requests submitted:
  - Validate CollectedClientData.crossOrigin in RP ops (by emlun)
    https://github.com/w3c/webauthn/pull/2166 [type:technical] [subtype:rp-ops] 
  - Fix Unicode example syntax (by emlun)
    https://github.com/w3c/webauthn/pull/2165 [type:editorial] [i18n-needs-resolution] 
  - Add [credential record/authenticatorDisplayName] handling to RP operations (by emlun)
    https://github.com/w3c/webauthn/pull/2163 [type:technical] [subtype:rp-ops] 
  - Deprecate rp.name (by emlun)
    https://github.com/w3c/webauthn/pull/2159 [type:technical] [subtype:rp-ops] 
  - Mark Android SafetyNet attestation as deprecated. (by agl)
    https://github.com/w3c/webauthn/pull/2155 

  5 pull requests received 8 new comments:
  - #2161 Fix CredentialRequestOptions hyperlink (1 by w3cbot)
    https://github.com/w3c/webauthn/pull/2161 
  - #2155 Mark Android SafetyNet attestation as deprecated. (4 by Firehed, agl, emlun, timcappalli)
    https://github.com/w3c/webauthn/pull/2155 
  - #2150 Exclude all platform authenticators that use self attesation from hav… (1 by agl)
    https://github.com/w3c/webauthn/pull/2150 [type:technical] 
  - #2145 Clarify behaviour of duplicate hints (1 by nsatragno)
    https://github.com/w3c/webauthn/pull/2145 [type:technical] [subtype:underspecifiedBehaviors] [@Risk] 
  - #2111 Cleanup: Manual References (1 by emlun)
    https://github.com/w3c/webauthn/pull/2111 [type:editorial] 


Repositories tracked by this digest:
-----------------------------------
* https://github.com/w3c/webauthn


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Tuesday, 1 October 2024 17:00:36 UTC