Monday, 30 September 2024
- Re: [webauthn] Mark Android SafetyNet attestation as deprecated. (#2155)
- Re: [webauthn] Mark Android SafetyNet attestation as deprecated. (#2155)
- Re: [webauthn] authenticatorDisplayName should use a localizable language map (#2151)
- Re: [webauthn] authenticatorDisplayName should use a localizable language map (#2151)
- [webauthn] Pull Request: Add [credential record/authenticatorDisplayName] handling to RP operations
- [w3c/webauthn] e2ab21: Add aliased link texts for "human palatability"
- [webauthn] new commits pushed by emlun
- Re: [webauthn] Add `authenticatorDisplayName` to Step 27 and Step 23 of the registration and authentication ceremonies respectively (#2156)
- Re: [webauthn] Add `challengeUrl` (#2152)
Friday, 27 September 2024
- Re: [webauthn] U+ notation incorrect (#1641)
- Re: [webauthn] Unicode "tag" characters are deprecated for language tagging (#1642)
- Re: [webauthn] Mechanism for encoding *direction* metadata may need more work (#1644)
- Re: [webauthn] [Editorial] Truncation description inaccurate (#1645)
- Re: [webauthn] Trailing position of metadata (#1646)
- Re: [webauthn] Use of in-field metadata not preferred (#1643)
- Re: [webauthn] Fix CredentialRequestOptions hyperlink (#2161)
- Re: [webauthn] Fix CredentialRequestOptions hyperlink (#2161)
- [webauthn] Pull Request: Fix CredentialRequestOptions hyperlink
- [webauthn] Authentication ceremony _`options.`_`publicKey` has the wrong hyperlink (#2160)
- [webauthn] Pull Request: Deprecate rp.name
- [w3c/webauthn] 2e2e3c: Deprecate rp.name
- [webauthn] new commits pushed by emlun
- Re: [webauthn] Add `challengeUrl` (#2152)
Thursday, 26 September 2024
- Closed: [webauthn] Reconciling with FedCM errors (#2158)
- Re: [webauthn] Exclude all platform authenticators that use self attesation from hav… (#2150)
- Re: [webauthn] Exclude all platform authenticators that use self attesation from hav… (#2150)
- Re: [webauthn] Should credentials requested with attestation=none include an AAGUID? (#1962)
- Re: [webauthn] Reconciling with FedCM errors (#2158)
- [webauthn] Reconciling with FedCM errors (#2158)
- Re: [webauthn] Providing AAGUID on Get (#2157)
- Re: [webauthn] Providing AAGUID on Get (#2157)
- Re: [webauthn] Providing AAGUID on Get (#2157)
- [webauthn] Providing AAGUID on Get (#2157)
- Re: [webauthn] Add `authenticatorDisplayName` to Step 27 and Step 23 of the registration and authentication ceremonies respectively (#2156)
- Re: [webauthn] Add `authenticatorDisplayName` to Step 27 and Step 23 of the registration and authentication ceremonies respectively (#2156)
- [webauthn] Add `authenticatorDisplayName` to Step 27 and Step 23 of the registration and authentication ceremonies respectively (#2156)
Wednesday, 25 September 2024
- Re: [webauthn] Add `challengeUrl` (#2152)
- Re: [webauthn] Add `challengeUrl` (#2152)
- Re: [webauthn] Add `challengeUrl` (#2152)
- Re: [webauthn] Add `challengeUrl` (#2152)
- Re: [webauthn] authenticatorDisplayName should use a localizable language map (#2151)
- Re: [webauthn] Mark Android SafetyNet attestation as deprecated. (#2155)
- [w3c/webauthn] bd15e8: Initial packed enterprise attestation requirements.
- [webauthn] new commits pushed by agl
- [webauthn] Pull Request: Mark Android SafetyNet attestation as deprecated.
- [w3c/webauthn] bcd428: Mark Android SafetyNet attestation as deprecated.
- [webauthn] new commits pushed by agl
- Re: [webauthn] Add `challengeUrl` (#2152)
- Re: [webauthn] Add `challengeUrl` (#2152)
- Re: [webauthn] Bit set by the SPC extension should backed up as part of the Public Key Credential Source (#2153)
- [webauthn] Bit set by the SPC extension should backed up as part of the Public Key Credential Source (#2153)
- Re: [webauthn] Should credentials requested with attestation=none include an AAGUID? (#1962)
- Re: [webauthn] Allow `platform`-based self attestation with non-zero AAGUID when `AttestationConveyancePreferenceOption` `"none"` is used (#2146)
Tuesday, 24 September 2024
- Event Invitation: Web Payments Working Group, Web Authentication Working Group Joint Meeting
- Re: [webauthn] authenticatorDisplayName should use a localizable language map (#2151)
- [webauthn] Add `challengeUrl` (#2152)
- Re: [webauthn] Surface platform authenticator status in the `create` (and maybe `get`) response / help RPs track UV/PA/RK (#1567)
- Re: [webauthn] Should credentials requested with attestation=none include an AAGUID? (#1962)
- Re: [webauthn] Allow `platform`-based self attestation with non-zero AAGUID when `AttestationConveyancePreferenceOption` `"none"` is used (#2146)
- Closed: [webauthn] undefined terms and terms we really ought to define (#462)
- Re: [webauthn] Cleanup: Manual References (#2111)
- Re: [webauthn] authenticatorDisplayName should use a localizable language map (#2151)
- Closed: [webauthn] Minor cleanups from PR 1270 review (#1291)
- Re: [webauthn] Minor cleanups from PR 1270 review (#1291)
- Re: [webauthn] Requesting properties of created credentials. (#1449)
- Closed: [webauthn] Requesting properties of created credentials. (#1449)
- Re: [webauthn] Adding info about HSTS for the RPID to client Data. (#1554)
- Re: [webauthn] Adding info about HSTS for the RPID to client Data. (#1554)
- Closed: [webauthn] Adding info about HSTS for the RPID to client Data. (#1554)
- [webauthn] authenticatorDisplayName should use a localizable language map (#2151)
- Event Updated: Web Authentication Working Group
- Event Updated: Web Authentication Working Group
- Re: [webauthn] Cross origin authentication without iframes (accommodating SPC in WebAuthn) (#1667)
- Closed: [webauthn] Cross origin authentication without iframes (accommodating SPC in WebAuthn) (#1667)
- Re: [webauthn] Syncing Platform Keys, Recoverability and Security levels (#1640)
- Closed: [webauthn] Syncing Platform Keys, Recoverability and Security levels (#1640)
- Closed: [webauthn] Possible experiences in a future WebAuthn (#1637)
- Re: [webauthn] Cross-origin credential creation in iframes (#1656)
- Closed: [webauthn] Cross-origin credential creation in iframes (#1656)
- Re: [webauthn] Clarify behaviour of duplicate hints (#2145)
- Closed: [webauthn] Ambiguous instructions in the Android Key Attestation Statement Format verification procedure (#1980)
- Re: [webauthn] Allow desired attestation format to be an ordered list (#1917)
- Closed: [webauthn] Allow desired attestation format to be an ordered list (#1917)
- Weekly github digest (WebAuthn)
- Re: [webauthn] Clarify behaviour of duplicate hints (#2145)
- Re: [webauthn] Should credentials requested with attestation=none include an AAGUID? (#1962)
- [w3c/webauthn] 8fcd85: Merge pull request #1954 from dwaite/enterprise-at...
- [webauthn] new commits pushed by github-actions[bot]
- [w3c/webauthn] bd15e8: Initial packed enterprise attestation requirements.
- [webauthn] new commits pushed by dwaite
- Closed: [webauthn] Describe packed enterprise attestation (#1916)
- [webauthn] Merged Pull Request: Enterprise packed attestation guidance
- Re: [webauthn] Ambiguous instructions in the Android Key Attestation Statement Format verification procedure (#1980)
- [w3c/webauthn] 7aec74: Replace UserCancellationError with OptOutError
- [webauthn] new commits pushed by MasterKale
- Re: [webauthn] Add userName and userDisplayName to webdriver (#2148)
- Re: [webauthn] Clarify behaviour of duplicate hints (#2145)
- [w3c/webauthn] 4c4698: Merge pull request #2149 from dwaite/remove-packed...
- [webauthn] new commits pushed by github-actions[bot]
- [w3c/webauthn] 176ea8: Remove prior bikeshed workaround
- [webauthn] Merged Pull Request: Remove bikeshed workaround
- [webauthn] new commits pushed by dwaite
- [w3c/webauthn] 715072: Merge pull request #2134 from w3c/issue-2132-obsol...
- [webauthn] new commits pushed by github-actions[bot]
- [w3c/webauthn] 2e2818: Merge pull request #1926 from sbweeden/sbweeden_1925
- [webauthn] new commits pushed by github-actions[bot]
- [w3c/webauthn]
- [w3c/webauthn] e0fb9b: Update obsolete privacy concerns about throwing er...
- Closed: [webauthn] Review privacy concerns around error conditions (#2132)
- [webauthn] Merged Pull Request: Update obsolete privacy concerns about throwing errors early
- [webauthn] new commits pushed by emlun
- [w3c/webauthn] c92aec: Clarify TPM attestation verification instructions
- Re: [webauthn] Clarify behaviour of duplicate hints (#2145)
- Closed: [webauthn] TPM attestation verification steps inconsistent with FIDO conformance testing tool (#1925)
- [webauthn] new commits pushed by nicksteele
- [webauthn] Merged Pull Request: Clarify TPM attestation verification instructions
- [w3c/webauthn]
- [w3c/webauthn] 85abf6: Merge pull request #2145 from w3c/issue-2135-dupli...
- [webauthn] new commits pushed by github-actions[bot]
- [w3c/webauthn]
- [w3c/webauthn] 693a49: Clarify behaviour of duplicate hints
- Closed: [webauthn] Clarify behaviour of duplicate hints (#2135)
- [webauthn] Merged Pull Request: Clarify behaviour of duplicate hints
- [webauthn] new commits pushed by timcappalli
- [w3c/webauthn] c9cf9a: Merge pull request #2126 from w3c/issue-2122-rp-up...
- [webauthn] new commits pushed by github-actions[bot]
- [w3c/webauthn]
- [w3c/webauthn] 115c2f: Clarify meaning of "unless" in UP flag validation
- [webauthn] Merged Pull Request: Clarify meaning of "unless" in UP flag validation
- [webauthn] new commits pushed by emlun
- Re: [webauthn] Clarify meaning of "unless" in UP flag validation (#2126)
- [w3c/webauthn] 6cae8a: Reword UP flag validation per review suggestion
- [webauthn] new commits pushed by emlun
- Event Updated: Web Authentication Working Group
Monday, 23 September 2024
Saturday, 21 September 2024
Friday, 20 September 2024
- Re: [webauthn] Add "sign" extension (#2078)
- Re: [webauthn] Cross-window `Virtual Authenticator Database` (#2117)
Thursday, 19 September 2024
Wednesday, 18 September 2024
- [w3c/webauthn]
- [webauthn] new commits pushed by agl
- [w3c/webauthn]
- [webauthn] Pull Request: Remove bikeshed workaround
- Re: [webauthn] Remove rp.name (#2121)
- Re: [webauthn] Enterprise packed attestation guidance (#1954)
- [w3c/webauthn]
- [w3c/webauthn]
- [w3c/webauthn]
- [w3c/webauthn]
- [w3c/webauthn]
- [w3c/webauthn]
- [w3c/webauthn]
- [w3c/webauthn]
- [w3c/webauthn] 2e9018: Merge pull request #2129 from w3c/2112-tc-hints-to...
- [webauthn] new commits pushed by github-actions[bot]
- [w3c/webauthn]
- [w3c/webauthn] f91121: s/PublicKeyCredentialHints/PublicKeyCredentialHint
- Closed: [webauthn] Rename PublicKeyCredentialHints to PublicKeyCredentialHint? (#2112)
- [webauthn] new commits pushed by nicksteele
- [webauthn] Merged Pull Request: Rename PublicKeyCredentialHints to PublicKeyCredentialHint
- Re: [webauthn] Enterprise packed attestation guidance (#1954)
- Re: [webauthn] Enterprise packed attestation guidance (#1954)
- Re: [webauthn] Enterprise packed attestation guidance (#1954)
- Re: [webauthn] Enterprise packed attestation guidance (#1954)
- [w3c/webauthn] bd15e8: Initial packed enterprise attestation requirements.
- [webauthn] new commits pushed by dwaite
- [webauthn] Pull Request: Add userName and userDisplayName to webdriver
Tuesday, 17 September 2024
Monday, 16 September 2024
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- Re: [webauthn] Mustafacco (#2147)
- Closed: [webauthn] Mustafacco (#2147)
- [webauthn] Mustafacco (#2147)
- Re: [webauthn] Requiring user activation to call WebAuthn API (#1293)
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- Re: [webauthn] Requiring user activation to call WebAuthn API (#1293)
- Re: [webauthn] Requiring user activation to call WebAuthn API (#1293)
- Re: [webauthn] Requiring user activation to call WebAuthn API (#1293)
Saturday, 14 September 2024
Thursday, 12 September 2024
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- Re: [webauthn] Allow `platform`-based self attestation with non-zero AAGUID when `AttestationConveyancePreferenceOption` `"none"` is used (#2146)
- Re: [webauthn] Add topOrigin to the limited verification algorithm. (#2104)
- Re: [webauthn] Add topOrigin to the limited verification algorithm. (#2104)
- [w3c/webauthn]
- [w3c/webauthn] a0a8d1: Merge pull request #2104 from zacknewman/zacknewma...
- [webauthn] new commits pushed by github-actions[bot]
- [w3c/webauthn] 8d32e8: Update index.bs
- Closed: [webauthn] Add `topOrigin` to the limited verification algorithm (#2102)
- [webauthn] new commits pushed by nadalin
- [webauthn] Merged Pull Request: Add topOrigin to the limited verification algorithm.
Wednesday, 11 September 2024
- [w3c/webauthn] c5a109: Merge pull request #2138 from w3c/2136-tc-dfn-passkey
- [webauthn] new commits pushed by github-actions[bot]
- [w3c/webauthn] 06340f: Add dfn for passkey in passkey platform authentica...
- Closed: [webauthn] Add dfn for passkey in passkey platform authenticator (#2136)
- [webauthn] Merged Pull Request: Adds dfn for passkey in passkey platform authenticator and exports
- [webauthn] new commits pushed by agl
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- PR #2104
- Re: [webauthn] Rename PublicKeyCredentialHints to PublicKeyCredentialHint (#2129)
- Re: [webauthn] Cross-window `Virtual Authenticator Database` (#2117)
- Re: [webauthn] Remove rp.name (#2121)
- Re: [webauthn] Remove rp.name (#2121)
- Re: [webauthn] Enum values that ignore naming conventions in Web Authentication: An API for accessing Public Key Credentials - Level 3 (#2133)
- Closed: [webauthn] Enum values that ignore naming conventions in Web Authentication: An API for accessing Public Key Credentials - Level 3 (#2133)
- [w3c/webauthn] ca2836: Merge pull request #2127 from w3c/issue-2045-seman...
- [webauthn] new commits pushed by github-actions[bot]
- [w3c/webauthn] 512fe4: Add editorial conventions section to CONTRIBUTING.md
- [webauthn] new commits pushed by selfissued
- Closed: [webauthn] Editorial convention: Semantic line breaks (#2045)
- [webauthn] Merged Pull Request: Codify semantic line breaks as editorial convention
- [w3c/webauthn] 2e4e2e: Merge pull request #2141 from w3c/2064-tc-bebs-steps
- [webauthn] new commits pushed by github-actions[bot]
- [w3c/webauthn]
- [w3c/webauthn] ad88a3: add BE/BS steps to authData
- Closed: [webauthn] §6.1. Steps to generate authenticator data should include BE and BS flags (#2064)
- [webauthn] new commits pushed by emlun
- [webauthn] Merged Pull Request: Add BE/BS steps to authData generation
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- [webauthn] Allow `platform`-based self attestation with non-zero AAGUID when `AttestationConveyancePreferenceOption` `"none"` is used (#2146)
- [w3c/webauthn] 3361ef: Explicitly specify binary encoding for string trun...
- [webauthn] new commits pushed by emlun
- Re: [webauthn] Add "sign" extension (#2078)
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- [w3c/webauthn] caf217: Update index.bs
- [webauthn] new commits pushed by timcappalli
- [webauthn] Pull Request: Clarify behaviour of duplicate hints
- [w3c/webauthn] 693a49: Clarify behaviour of duplicate hints
- [webauthn] new commits pushed by emlun
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- 09/11/2024 W3C Web Authentication Meeting Agenda
- Event Invitation: Web Authentication weekly
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
Tuesday, 10 September 2024
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- Re: [webauthn] Allow Conditional Mediation without autofill (#2144)
- [webauthn] Allow Conditional Mediation without autofill (#2144)
- [webauthn] Add `userName` and `userDisplayName` to WebDriver's `Credential Parameters` JSON object (#2143)
- Weekly github digest (WebAuthn)
Monday, 9 September 2024
- Re: [webauthn] Which "pubKeyCredParams" to use? (#1757)
- Re: [webauthn] Which "pubKeyCredParams" to use? (#1757)
Saturday, 7 September 2024
- Closed: [webauthn] b2d82c59b7ac12d738d678359af0bbdd9b95b43d (#2142)
- [webauthn] b2d82c59b7ac12d738d678359af0bbdd9b95b43d (#2142)
Friday, 6 September 2024
- [w3c/webauthn] 823ce1: s/MUST not/MUST NOT
- [webauthn] new commits pushed by timcappalli
- [webauthn] Pull Request: Add BE/BS steps to authData generation
- [w3c/webauthn] ad88a3: add BE/BS steps to authData
- [webauthn] new commits pushed by timcappalli
- Re: [webauthn] Public Key Credential Source and Extensions (#1719)
- [w3c/webauthn]
- [w3c/webauthn] ee25ba: Rename first-factor roaming authenticator and inte...
- [webauthn] Merged Pull Request: Rename first-factor roaming authenticator and integrate passkey term …
- [webauthn] new commits pushed by emlun
- [webauthn] Pull Request: Rename first-factor roaming authenticator and integrate passkey term …
- [w3c/webauthn] ee25ba: Rename first-factor roaming authenticator and inte...
- [webauthn] new commits pushed by emlun
- Re: [webauthn] Should enterprise attestation support be flagged explicitly? (#1742)
- Closed: [webauthn] Should enterprise attestation support be flagged explicitly? (#1742)
- [webauthn] Pull Request: Update Use Cases for L3
- [w3c/webauthn] 0e580b: first pass at use case updates
- [webauthn] new commits pushed by timcappalli
- [webauthn] Pull Request: Adds dfn for passkey in passkey platform authenticator and exports
- [w3c/webauthn] 06340f: Add dfn for passkey in passkey platform authentica...
- [webauthn] new commits pushed by timcappalli
- [w3c/webauthn]
- Re: [webauthn] Adds dfn for passkey in passkey platform authenticator (#2137)
- [webauthn] Closed Pull Request: Adds dfn for passkey in passkey platform authenticator
- [webauthn] Pull Request: Adds dfn for passkey in passkey platform authenticator
- [w3c/webauthn] e8934e: Add dfn for passkey in passkey platform authenticator
- [webauthn] new commits pushed by timcappalli
- [webauthn] Add dfn for passkey in passkey platform authenticator (#2136)
- Re: [webauthn] Clarify behaviour of duplicate hints (#2135)
- [webauthn] Clarify behaviour of duplicate hints (#2135)
Thursday, 5 September 2024
- Re: [webauthn] Always PRF enabled:false (#1857)
- Re: [webauthn] Always PRF enabled:false (#1857)
- Re: [webauthn] What is the point of `allowCredentials`? (#867)
Wednesday, 4 September 2024
- Initial signal* methods implementation available on Chrome
- 09/04/2024 W3C Web Authentication Meeting Agenda Cancelled
- [webauthn] Pull Request: Update obsolete privacy concerns about throwing errors early
- [w3c/webauthn] e0fb9b: Update obsolete privacy concerns about throwing er...
- [webauthn] new commits pushed by emlun
- Re: [webauthn] What is the point of `allowCredentials`? (#867)
- Re: [webauthn] Review privacy concerns around error conditions (#2132)
- Re: [webauthn] What is the point of `allowCredentials`? (#867)
- Re: [webauthn] Review privacy concerns around error conditions (#2132)