Open MasterKale opened 1 month ago
WebAuthn L3 is being updated with explicit verification steps for the clientDataJSON.crossOrigin flag:
clientDataJSON.crossOrigin
https://github.com/w3c/webauthn/pull/2166
I should update both verifyRegistrationResponse() and verifyAuthenticationResponse() to support verifying this flag accordingly for RP's that might care to know:
verifyRegistrationResponse()
verifyAuthenticationResponse()
https://github.com/MasterKale/SimpleWebAuthn/blob/dc70416e781c9ab11625ba9afbf092809391874e/packages/server/src/helpers/decodeClientDataJSON.ts#L18
Reopening this to take another stab. I reverted the initial attempt for now:
https://github.com/MasterKale/SimpleWebAuthn/pull/626
Describe the issue
WebAuthn L3 is being updated with explicit verification steps for the
clientDataJSON.crossOrigin
flag:https://github.com/w3c/webauthn/pull/2166
I should update both
verifyRegistrationResponse()
andverifyAuthenticationResponse()
to support verifying this flag accordingly for RP's that might care to know:https://github.com/MasterKale/SimpleWebAuthn/blob/dc70416e781c9ab11625ba9afbf092809391874e/packages/server/src/helpers/decodeClientDataJSON.ts#L18