Closed samuelgoto closed 3 months ago
That code implies to me that the rejection is being delayed...
I checked and we do delay the rejection, as expected. Thus it is not the case that the browser reveals this information to the RP, as it is indistinguisable from the user closing the dialog once it shows up. Closing
Currently, if no IdPs registered in the past, the browser reveals to the RP that fact, which could potentially be a breach of the user's privacy.
I'm not sure what the answer is, but I ran into this while testing this, so should be easily reproducible:
https://x.com/samuelgoto/status/1793776387356340357