[Webkit-unassigned] [Bug 224350] New: Asserting WebAuthn credentials via allowCredentials fails

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Thu Apr 8 17:11:00 PDT 2021


https://bugs.webkit.org/show_bug.cgi?id=224350

            Bug ID: 224350
           Summary: Asserting WebAuthn credentials via allowCredentials
                    fails
           Product: WebKit
           Version: Safari 14
          Hardware: Unspecified
                OS: macOS 11
            Status: NEW
          Severity: Normal
          Priority: P2
         Component: WebKit Misc.
          Assignee: webkit-unassigned at lists.webkit.org
          Reporter: martinkr at google.com

Created attachment 425562

  --> https://bugs.webkit.org/attachment.cgi?id=425562&action=review

Screencast of behavior with USB security key attached

In Safari 14.0.3, when I create a WebAuthn credential with the platform authenticator, e.g. on webauthntest.azurewebsites.net, Safari fails to assert that credential when the get() call passes the credential identifier in the allowCredentials parameter *as long as a USB security key happens to be connected to the machine*. Asserting the credential via an empty allowCredentials parameter works (shows the account selector). If no USB security key is connected, asserting with empty or non-empty allow list both work. This is likely another flavor of the bug already reported in https://bugs.webkit.org/show_bug.cgi?id=219814.

-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-unassigned/attachments/20210409/7c0d4307/attachment.htm>


More information about the webkit-unassigned mailing list