Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Backup of the payment bit should be defined in SPC spec #278

Open
timcappalli opened this issue Nov 25, 2024 · 0 comments
Open

Backup of the payment bit should be defined in SPC spec #278

timcappalli opened this issue Nov 25, 2024 · 0 comments

Comments

@timcappalli
Copy link
Member

@stephenmcgruer there was a discussion earlier in the year / last year around ensuring that the payment bit was stored with and backed up with the WebAuthn credential. I believe the core reason was to ensure the bit was available across WebAuthn clients, and the secondary reason was to ensure the bit was still present on a new device.

We discussed in WebAuthn WG (w3c/webauthn#2153) and came to the conclusion that the SPC spec should state this, as the extension is wholly defined in this spec.

I think it could be as simple as:

"The payment bit MUST be stored with the Public Key Credential Source and MUST be backed up for [=backup eligible=] credentials."

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant