Post

Replies

Boosts

Views

Activity

Reply to How to specify the excludedCredentials when a passkey is created?
garrett-davidson Thank you for your reply! (I try to Add a Comment, but it looks not working ...) The experience of using it in the spec is strange: to the user they go through the full registration and it looks like they got a new credential, but behind the scenes the developer got an error saying they already had a credential. I see... if my understanding is correct, in this case, the client(browser/mobile os) should return an error instead to create a new credential according to the WebAuthn spec. https://www.w3.org/TR/webauthn-2/#dom-publickeycredentialcreationoptions-excludecredentials But the looks like they got a new credential means that the finish of local biometrics authentication looks like a new credential is created from a user point of view, right...? Can you file this request through Feedback Assistant? Please explain the use case you have in mind where a user might actually go through a registration flow while they have an existing credential and not expect to get a new one. I sent Feedback also. https://feedbackassistant.apple.com/feedback/11943515 But there was not so detailed explanation of the use case. So I will add it!
Topic: Privacy & Security SubTopic: General Tags:
Jan ’23