Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security checks in [[DiscoverFromExternalSource]] don't match those described in the security section #38

Open
mkruisselbrink opened this issue Mar 26, 2020 · 0 comments

Comments

@mkruisselbrink
Copy link

In https://wicg.github.io/WebOTP/#security-availability you describe a number of checks, yet the actual algorithm instead checks if the origin is opaque. As such it is unclear (to me) what the actual limitations for usage are.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant