Skip to content

issues Search Results · repo:w3c/webauthn language:HTML

Filter by

1k results
 (74 ms)

1k results

inw3c/webauthn (press backspace or delete to remove)

In Section 9 of the specification (WebAuthn Extensions), it is stated that Every extension is a client extension, meaning that the extension involves communication with and processing by the client. Such ...
type:technical
  • joshzhao
  • 9
  • Opened 
    18 hours ago
  • #2331

Do we have deployment experience yet with user handles to evaluate whether RPs are complying with the in-spec advice? I would expect advice to relying parties to definitely not put user email addresses ...
privacy-tracker
type:technical
  • npdoty
  • 1
  • Opened 
    5 days ago
  • #2324

Is user verification discouraged intended to be used for relying parties to signal a preference for less user interaction? Does user verification provide a certain backstop of privacy protection for users ...
privacy-tracker
type:editorial
  • npdoty
  • 1
  • Opened 
    5 days ago
  • #2323

https://www.w3.org/TR/2025/WD-webauthn-3-20250127/#enum-hints This was confusing terminology to me. User-agent Hints sounds very similar to client hints , but is actually rather the opposite. These are ...
type:editorial
  • npdoty
  • 1
  • Opened 
    5 days ago
  • #2322

Is this intended to support signing in to one relying party when that party is embedded on a different site? Are users supposed to distinguish which party they are signing into when they do this? That ...
privacy-needs-resolution
type:technical
  • npdoty
  • 1
  • Opened 
    5 days ago
  • #2321

The client’s support or lack of support of a WebAuthn capability may pose a fingerprinting risk. Client implementations MAY wish to limit capability disclosures based on client policy and/or user consent. ...
privacy-needs-resolution
type:technical
  • npdoty
  • 1
  • Opened 
    5 days ago
  • #2320

Although Credential IDs and credential public keys are necessarily shared with the WebAuthn Relying Party to enable strong authentication, they are designed to be minimally identifying and not shared between ...
privacy-needs-resolution
type:technical
  • npdoty
  • Opened 
    5 days ago
  • #2319

Proposed Change Section 6.5.5. is titled Signature Formats for Packed Attestation, FIDO U2F Attestation, and Assertion Signatures . Because its description of signature formats covers both attestation ...
type:editorial
  • dannyniu
  • 3
  • Opened 
    7 days ago
  • #2318

Background In section 6.5.5 Signature Formats for Packed Attestation, FIDO U2F Attestation, and Assertion Signatures , it is stated that the sig value MUST be encoded as an ASN.1 DER Ecdsa-Sig-Value . ...
stat:pr-open
type:editorial
  • rlin1
  • 1
  • Opened 
    on Jul 15
  • #2314

Use case The use case is simple. Having an app with one button Sign-in with passkey . If user does not have an account with their device, one is created for them. If they do have, they are signed-in. ...
stat:Discuss
subtype:FeatureProposal
  • mitar
  • 6
  • Opened 
    on Jul 11
  • #2313
Issue origami icon

Learn how you can use GitHub Issues to plan and track your work.

Save views for sprints, backlogs, teams, or releases. Rank, sort, and filter issues to suit the occasion. The possibilities are endless.Learn more about GitHub Issues
ProTip! 
Press the
/
key to activate the search input again and adjust your query.
Issue origami icon

Learn how you can use GitHub Issues to plan and track your work.

Save views for sprints, backlogs, teams, or releases. Rank, sort, and filter issues to suit the occasion. The possibilities are endless.Learn more about GitHub Issues
ProTip! 
Press the
/
key to activate the search input again and adjust your query.
Issue search results · GitHub