Determine 'trusted authenticators' switch at runtime

Description

The predicate used to ‘ask for' attestation is dynamic and could be different for different types of users. However, the check that determines if the authenticator is trusted based on this attestation is global, either on or off. This is because it is a flag inside the Yubico RelyingParty object that is set on initialisation of the RP object. I’ll check if there is a way to set this per registration.

 

As suggested by .

Environment

None

Activity

Details

Assignee

Reporter

Affects versions

Created January 6, 2025 at 12:31 PM
Updated January 6, 2025 at 12:31 PM

Flag notifications