[Webkit-unassigned] [Bug 266452] New: [Webauthn] NFC read unresponsive when doing Get() + allowList with any transport hint even `nfc`

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Thu Dec 14 19:17:15 PST 2023


https://bugs.webkit.org/show_bug.cgi?id=266452

            Bug ID: 266452
           Summary: [Webauthn] NFC read unresponsive when doing Get() +
                    allowList with any transport hint even `nfc`
           Product: WebKit
           Version: Safari 17
          Hardware: Mac (Intel)
                OS: macOS 13
            Status: NEW
          Severity: Normal
          Priority: P2
         Component: WebKit Misc.
          Assignee: webkit-unassigned at lists.webkit.org
          Reporter: nuno.sung at authentrend.com

[Environment]
- macOS 13.5.2
- Browser
  - Safari 17.2
  - STP 17.4 (18618.1.7.1.1)
- NFC Reader : HID 5422 CL
- Security key: Yubikey NFC
[Steps]
1. Use test site https://webauthn.me/debugger, as this can select to send allowList with transport or not.
2. Register a credential into the security key with any settings through NFC or USB
3. Authenticate it with website UI to check 1)allowCredentials and 2)transports with NFC selected.
4. webauthn UI is showing UI to ask to 

[Issues]
1. The NFC security key doesn't react to the webauthn dialog and seems no data are transferring.
2. If remove above transport hint, the Get() can work well with NFC security key.
3. Some websites likes appleid.apple.com/Binance will force to send allowList with transport hint can let them can' work on macOS as this issue.
4. No this issue on iOS 16.7.1 safari with the same setting.

-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-unassigned/attachments/20231215/edb5627e/attachment.htm>


More information about the webkit-unassigned mailing list