webauthn icon indicating copy to clipboard operation
webauthn copied to clipboard

CollectedClientData.crossOrigin not referenced in RP ops

Open emlun opened this issue 6 months ago • 1 comments

Both §7. WebAuthn Relying Party Operations instructs to validate CollectedClientData.origin and .topOrigin (if present), but do not reference crossOrigin at all.

Proposed Change

Add a step to verify crossOrigin in the RP operations. For example:

emlun avatar Aug 07 '24 14:08 emlun