Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Note that a UA may create a new credential from the selection UI #18

Open
mnoorenberghe opened this issue May 18, 2016 · 0 comments · May be fixed by #44
Open

Note that a UA may create a new credential from the selection UI #18

mnoorenberghe opened this issue May 18, 2016 · 0 comments · May be fixed by #44

Comments

@mnoorenberghe
Copy link
Member

I think it may be useful to note in "Request a SiteBoundCredential with user mediation" step 2 and/or "Credential Selection" that a UA could provide UI to allow the user to use a PasswordCredential that isn't already stored by the UA.
This would improve:

  • the UX for cases where the user wants to use a credential other than one that is currently saved (perhaps without saving it permanently this time either) so the user can use the trusted UI consistently for the site
  • security for the initial capture of the password credential which is otherwise usually captured from regular <input> which could be read by an attacker via XSS
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant