<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>203200</bug_id>
          
          <creation_ts>2019-10-21 12:31:46 -0700</creation_ts>
          <short_desc>[WebAuthn] Support appidExclude enrollment extension</short_desc>
          <delta_ts>2022-06-30 17:26:14 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebCore Misc.</component>
          <version>Safari Technology Preview</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>NEW</bug_status>
          <resolution></resolution>
          
          <see_also>https://bugs.webkit.org/show_bug.cgi?id=181943</see_also>
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Casey Piper">piperc</reporter>
          <assigned_to name="pascoe@apple.com">pascoe</assigned_to>
          <cc>jiewen_tan</cc>
    
    <cc>nuno.sung</cc>
    
    <cc>pascoe</cc>
    
    <cc>piperc</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1581947</commentid>
    <comment_count>0</comment_count>
    <who name="Casey Piper">piperc</who>
    <bug_when>2019-10-21 12:31:46 -0700</bug_when>
    <thetext>For relying parties that previously enrolled security keys via the U2F enrollment protocol, keys are bound to an application identifier, rather than the relying party id to which WebAuthn enrollments are bound.

Since WebAuthn is meant to be backwards compatible with enrollments via U2F, the authentication extension appid can be provided during authentication [1]. Similarly, to prevent reregistration of the same credential when doing a WebAuthn enrollment, an extension [appidExclude] was added to the WebAuthn specification to first check if a key was enrolled via U2F before completing the WebAuthn enrollment [2][3] and report the key already registered if so.

[1] https://bugs.webkit.org/show_bug.cgi?id=143491
[2] https://github.com/w3c/webauthn/pull/1244
[3] https://w3c.github.io/webauthn/#sctn-appid-exclude-extension</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1581950</commentid>
    <comment_count>1</comment_count>
    <who name="Jiewen Tan">jiewen_tan</who>
    <bug_when>2019-10-21 12:36:43 -0700</bug_when>
    <thetext>Will track this in an upcoming level 2 umbrella.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1692643</commentid>
    <comment_count>2</comment_count>
    <who name="Jiewen Tan">jiewen_tan</who>
    <bug_when>2020-09-28 12:10:49 -0700</bug_when>
    <thetext>*** Bug 217050 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1879610</commentid>
    <comment_count>3</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2022-06-30 17:26:14 -0700</bug_when>
    <thetext>&lt;rdar://problem/96257224&gt;</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>