Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

discuss RP ID and how the RP may declare it such that creds are valid for subdomains #30

Open
equalsJeffH opened this issue Feb 18, 2021 · 0 comments

Comments

@equalsJeffH
Copy link
Contributor

equalsJeffH commented Feb 18, 2021

cf. https://w3c.github.io/webauthn/#relying-party-identifier

<someone> reports:
"Going over stack overflow webauthn posts I found two people running into this: they have two websites at domain.com & subdomain.domain.com. They register a key at domain.com and are surprised that it doesn't work on get assertion for subdomain.domain.com. The reason is they are not setting an RP ID of domain.com, instead leaving the default (which is the origin)."

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant