webauthn icon indicating copy to clipboard operation
webauthn copied to clipboard

Web Authentication: An API for accessing Public Key Credentials

Results 204 webauthn issues
Sort by recently updated
recently updated
newest added

AFAIK, in order to have terms that are defined -- e.g., `...` -- in the webauthn spec able to be used by reference in other W3C & WhatWG specs, they...

type:editorial
subtype:editorialConventions
stat:OnGoing
@Risk

The below terms are formally undefined and we should consider defining them (and linking their occurrences to their dfn. Be sure to see also issue #358 -- there is overlap...

type:editorial
stat:OnGoing
@Risk

When a relying party wishes to use attestations, the flow is one where the site presents the UX on what is acceptable, the user gestures an authenticator to create a...

stat:Discuss
subtype:FeatureProposal
subtype:Inquiry

This issue is to track progress on the addition of a network transport, which is mostly happening in FIDO world. Here is a summary of progress so far: * @arnar,...

type:technical

Can you help me understand the overall usernameless flow across attestation and assertion, especially in the context of maintaining user privacy? The main thing I'm trying to figure out is...

type:editorial

As I recall, we've verbally discussed the question of whether the WebAuthn API ought to be available to {service, web}workers (aka "Workers") but we do not have an issue tracking...

type:technical
subtype:algorithms/WebIDL
@Risk

Following the approach of the [Payment Handler API](https://www.w3.org/TR/payment-handler/), there could a way for a web application to get "installed" inside the user agent as an authenticator that end-users could then...

type:technical

..pointing back to credman's [section 7.1. Website Authors](https://www.w3.org/TR/credential-management-1/#implementation-authors), which briefly & explicitly explains that trying to use `if (!navigator.credentials) ...` is suboptimal for feature detection, rather `if (!window.PublicKeyCredential) ...` ought...

type:editorial

When John Doe registers a new key with an RP, using a platform authenticator on a computing device, his newly generated private key is bound to that platform authenticator on...

type:technical

per @tabatkins: Tab: If you're using ``, that's very likely wrong. That's for providing all the info of an autolink, when a spec doesn't provide autolinks at all. There's a...

type:editorial
priority:low
@Risk