Re: [webauthn] Clarify relationship between PRF and hmac-secret extensions (#2298)

> This is incorrect - regardless of implementation backend, an `evalByCredential` argument during registration is nonsensical since the credential ID by definition cannot be known at that time. Its presence is therefore almost certainly a mistake on the RP's part, and we should fail early to help them catch that.

My use of “VVVVV” was meant as a “pointer” to the step that was wrong (i.e., I wasn’t claiming that step was wrong).

-- 
GitHub Notification of comment by zacknewman
Please view or discuss this issue at https://github.com/w3c/webauthn/pull/2298#issuecomment-2939996301 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 4 June 2025 13:13:38 UTC