Re: [webauthn] Feature Request: disableAutoSelect for PublicKeyCredentialRequestOptions (#2335)

> > it follows the current behavior of WebAuthn Clients, which already prioritize a transport in the initial prompt but still let users select a different authenticator if they wish.
> 
> No, it would not. Enforcement would mean only the options included in hints would be available to the user, which is how authenticator attachment behaves today (albeit with only two options), and why we are slowly getting rid of it.

Right—I guess what I’m suggesting isn’t limiting authenticator choice, but rather enforcing clients to use Client Hints to guide the initial UI—specifically, which transport gets prioritized when the prompt is first shown.

-- 
GitHub Notification of comment by jychab
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/2335#issuecomment-3348872473 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Monday, 29 September 2025 20:10:32 UTC