Re: [webauthn] Generalize PRF extension processing to non-CTAP authenticators (#2298)

Actually, there is something that needs to be improved still. For non-CTAP the motivation behind creating the "salts" instead of passing the inputs directly doesn't exist, so it's reasonable to assume that non-CTAP doesn't need to deal with the "salts". In the registration sections, there is no mention of the "salts" for non-CTAP; but in the authentication, there is mention.

If non-CTAP is expected to still use the "salts", then the registration section should be changed to talk about them.

-- 
GitHub Notification of comment by zacknewman
Please view or discuss this issue at https://github.com/w3c/webauthn/pull/2298#issuecomment-2970305356 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Friday, 13 June 2025 12:55:30 UTC