webauthn
webauthn copied to clipboard
Should enterprise attestation support be flagged explicitly?
At the June F2F, the topic of how painful it can be to require enterprise attestation came up. Right now browsers throw a type error if not supported, but that would turn into a request with no attestation after updating browsers to ignore unknown enum values. This is undesirable: RPs might want to know in advance whether enterprise attestation can succeed or not.
Is this a flag in WebAuthn that can be checked to see if the browser is going to throw a type error?
That would be helpful for RP.
You can't say if an enterprise attestation is available only if the browser supports the enum for enterprise attestation.
2023-08-30 meeting: address this as a client capability in #1923