WebAuthn timeout errors should wait to resolve promise until after user interaction |
|
Issue descriptionWebAuthn timeouts should not resolve the promise until the user has closed the timeout error dialog (if UI is enabled). This is permitted by the current spec wording and no spec changes are needed: "In order to prevent information leak that could identify the user without consent, this step MUST NOT be executed before lifetimeTimer has expired." |
|
►
Sign in to add a comment |
|
Comment 1 by kpaulhamus@chromium.org
, Jan 10Owner: kpaulhamus@chromium.org