FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

added userPresence check with userVerification = true by cheeeeenais · Pull Request #418 · cedarcode/webauthn-ruby · GitHub

added userPresence check with userVerification = true - #418

Open
cheeeeenais wants to merge 1 commit into
cedarcode:2-stablefrom
cheeeeenais:2-stable
Open

added userPresence check with userVerification = true#418
cheeeeenais wants to merge 1 commit into
cedarcode:2-stablefrom
cheeeeenais:2-stable

Conversation

Copy link
Copy Markdown

User Presence check is not checked in case User Verification is true.

Copy link
Copy Markdown
Contributor

Seems like this is intended: #74

I'm wondering... would it be possible for a response to have the UV set without having the UP flag set?

According to this thread that shouldn't be possible 🤔

Copy link
Copy Markdown
Contributor

Having said that I do think it makes sense to follow the Webauthn spec and always require the UP bit to be set.

I'm just trying to understand if this is actually a critical issue or not 🙂

cheeeeenais commented Jan 26, 2024 via email

Copy link
Copy Markdown
Author

Copy link
Copy Markdown
Contributor

Am I allowed to publish this finding in my research work?

Yeah, for sure!

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL