Re: [webauthn] Conditional create with existing passkey (#2296)

There is value in the overwrite behavior that exists for modal flows today, for scenarios like key rotation or key upgrades for PQC.

An RP shouldn't call conditional create if the sign in used a passkey unless they have an explicit reason to (e.g. key rotation / upgrade).

-- 
GitHub Notification of comment by timcappalli
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/2296#issuecomment-2912110876 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Tuesday, 27 May 2025 11:06:25 UTC