RESOLVED FIXED242091
[WebAuthn] Should reject rp with empty id
https://bugs.webkit.org/show_bug.cgi?id=242091
Summary [WebAuthn] Should reject rp with empty id
pascoe@apple.com
Reported 2022-06-28 16:39:23 PDT
Not specifying an rp.id should default to the caller’s origin's effective domain, but empty / null values should be rejected per spec. https://www.w3.org/TR/webauthn-2/#sctn-createCredential
Attachments
pascoe@apple.com
Comment 1 2022-06-28 16:41:26 PDT
EWS
Comment 2 2022-07-05 10:42:18 PDT
Committed 252142@main (3b920f82563c): <https://commits.webkit.org/252142@main> Reviewed commits have been landed. Closing PR #1879 and removing active labels.
Radar WebKit Bug Importer
Comment 3 2022-07-05 10:43:13 PDT
Note You need to log in before you can comment on or make changes to this bug.