You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The re-auth privacy considerations sections doesn't mention any mitigations for aligning user expectations of whether they are logged into an RP, with re-auth behavior.
For example, if a user deletes any storage associated with the RP (or all UA provided storage), there is a strong expectation that they will not be logged into the RP. In this case, future re-auth flows should fail until another standard flow has completed.
IIUC Chrome will ship to OT with a mitigation for this, so it would be good to at least highlight the importance in the explainer. I appreciate that the exact shape of the mitigation will be browser dependent, and may change over time, so a general statement about aligning with user expectations + example seems appropriate.
The text was updated successfully, but these errors were encountered:
The re-auth privacy considerations sections doesn't mention any mitigations for aligning user expectations of whether they are logged into an RP, with re-auth behavior.
For example, if a user deletes any storage associated with the RP (or all UA provided storage), there is a strong expectation that they will not be logged into the RP. In this case, future re-auth flows should fail until another standard flow has completed.
IIUC Chrome will ship to OT with a mitigation for this, so it would be good to at least highlight the importance in the explainer. I appreciate that the exact shape of the mitigation will be browser dependent, and may change over time, so a general statement about aligning with user expectations + example seems appropriate.
The text was updated successfully, but these errors were encountered: