Skip to content

update RP ID definition to allow URL syntax or arbitrary strings #1406

Description

@equalsJeffH

various web-enabled online services, such as SSH-in-the-browser are enabled using browser extensions (as one example) and do not have a classic domain-name-based host name, the latter being a (slightly loose) definition of an RP ID.

Given that the current RP ID definition is a proper subset of a URL (which is a subset of a URI), we ought to alter the WebAuthn spec's RP ID definition in order to officially accomodate these additional types of webauthn-wielding entities.

update 2020-07-01 1445h PT: see also issue #1372 "consider allowing cross-domain credential use"

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions