webauthn
webauthn copied to clipboard
Use of "valid domain" seems wrong
No user agent implements "valid domain". I suspect that instead you simply want to do a type check that the host of an origin is a domain.
Also, what kind of schemes can this origin have and do those need to be checked?