You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Note in section 1.1.2 we already assume the rpId to be passed to the authenticator: User sees a discreet prompt or notification, "Sign in to example.com."
What is the benefit of sending a hashed rpId? What kind of attack are we avoiding here? Passing an unhashed rpId allows for a UI that gives user more relevant information about what their gestures are meant for and ultimately helps user make more informed decision.
see: #154 (comment) where @leshi wrote:
see also: #176
The text was updated successfully, but these errors were encountered: