added userPresence check with userVerification = true#418
Open
cheeeeenais wants to merge 1 commit intocedarcode:2-stablefrom
Open
added userPresence check with userVerification = true#418cheeeeenais wants to merge 1 commit intocedarcode:2-stablefrom
cheeeeenais wants to merge 1 commit intocedarcode:2-stablefrom
Conversation
Contributor
|
Seems like this is intended: #74 I'm wondering... would it be possible for a response to have the According to this thread that shouldn't be possible 🤔 |
Contributor
|
Having said that I do think it makes sense to follow the Webauthn spec and always require the I'm just trying to understand if this is actually a critical issue or not 🙂 |
Author
|
Hey Santiago,It seems like nobody actually knows what UP is intended to be, as the specification is also rather vague. I think for completeness you can follow the standard by verifying always only UP (or by adding the UP=0 and UV=1 check). I don't believe this is anything critical. Am I allowed to publish this finding in my research work? Thanks in advance! Peizhou ChenOn 26 Jan 2024, at 19:58, Santiago Rodriguez ***@***.***> wrote:
Having said that I do think it makes sense to follow the Webauthn spec and always require the UP bit to be set.
I'm just trying to understand if this is actually a critical issue or not 🙂
—Reply to this email directly, view it on GitHub, or unsubscribe.You are receiving this because you authored the thread.Message ID: ***@***.***>
|
Contributor
Yeah, for sure! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
User Presence check is not checked in case User Verification is true.