Skip to content

Gap between BBK requirements and specification #321

@John-Earnshaw

Description

@John-Earnshaw

Spec: Gap between BBK requirements and specification

The BBK requirements document describes BBKs as having a strict 1-1 relationship with a tuple of (Browser instance, passkey, device). Currently the SPC specification does not describe how the tuple is formed or how the relationship is enforced.

  1. The Browser Bound Key Stores description "owned by the user agent" is ambiguous, and does not describe how a BBK is bound to a browser instance, additionally it does not prevent the user agent from holding many such stores.
  2. The binding process describes how a BBK may be associated with a passkey, but does not enforce an exclusive association (One BBK could be bound to many passkeys following this description)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions