Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Validate CollectedClientData.crossOrigin in RP ops #2166

Open
wants to merge 2 commits into
base: main
Choose a base branch
from

Conversation

emlun
Copy link
Member

@emlun emlun commented Oct 1, 2024

Fixes #2113.


Preview | Diff

Copy link
Contributor

@sbweeden sbweeden left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Marking "request changes" until @emlun confirms whether the wording around created is appropriate for the use in section 7.2 (verifying an assertion)

index.bs Outdated
@@ -6162,6 +6166,10 @@ a numbered step. If outdented, it (today) is rendered as a bullet in the midst o
See [[#sctn-validating-origin]] for guidance.
</li>

1. If <code>|C|.{{CollectedClientData/crossOrigin}}</code> is present and set to [TRUE],
verify that the [=[RP]=] expects that this credential would have been created within an iframe
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In this context, which is section 7.2 Verifying an Assertion, should we be saying created within an iframe, or used (for an assertion flow) within an iframe?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch, thanks!

@emlun emlun requested a review from sbweeden October 9, 2024 18:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

CollectedClientData.crossOrigin not referenced in RP ops
3 participants