generated from Firehed/php-library-template
-
-
Notifications
You must be signed in to change notification settings - Fork 3
Open
Milestone
Description
See the following for details:
https://www.w3.org/TR/webauthn-2/#sctn-username-enumeration
https://www.w3.org/TR/webauthn-2/#sctn-credential-id-privacy-leak
One possible approach here is to have CredentialContainer automatically insert bogus identifiers into the returned list. If so, the count, length, and order should all be randomized.
Metadata
Metadata
Assignees
Labels
No labels