private? 20:27:33 ...this is in a payments scenario. 20:28:00 ...do we need to change webauthn to help make the SPC call? 20:28:46 ...web auth spec needs to say a third party can be enabled. 20:28:56 jeffH: I think that is a web authn extension 20:29:17 aksay: in that context can I call with web authn 20:29:18 agl: no 20:29:30 ...it is payment request 20:29:40 jbradley: needs to be some sort of control. 20:29:47 ...not random RPs 20:30:07 ...we are still at the level of how this will work, rather than how APIs releate 20:30:49 akshay: has to come from SPC calll 20:31:24 jeffH: yes. jeff explains 20:31:44 akshay: what if RP sets this extension and does not use SPC 20:31:54 agl: that is not the way it was intended. 20:32:07 jbradley: there are restrictions, need to say that someplace 20:32:44 ...could bve signifacnt changes on how webauthn works. 20:34:24 agl: i don't believe normal web authn creds can be used in SPC space 20:34:33 jbradley: this is what banks are asking for 20:34:47 agl: looking at different contexts. 20:35:08 jbradley: depends on how it is flagging. it determines behavior 20:35:37 ...can separate the credentials for webauthn and spc. the topic of the other issue was to combine. 20:36:19 agl: that want one credential to solve all the problems 20:36:53 jbradley: spc is going back and forth on this. 20:37:12 ...one thing is two categories of creds. first party and third party 20:37:31 ...we could lose the filter of this credential is only good for authentication 20:37:52 ...comes down to three different credentials, some good for multiple things 20:37:59 ...storage is tricky part. 20:38:16 ...only tough the SPC logic and not first part. 20:38:23 touch 20:38:45 ...waiting for a good idea here. 20:38:58 agl: aren't these good ideas. 20:39:18 jbradley: it can work, doesn't feel clean. 20:39:25 ...could get conflict 20:40:01 elundberg: using userID is not the best idea. 20:40:28 jbradley talking about credential management API; but that could means changes to CTAP 2.1 20:40:44 elundberg: there is a drawback. 20:41:17 jbradley: almost a new data member rather than re-using cred blob 20:41:29 ...not much cred blob deployment 20:41:45 akshay: opinion, both ideas I really do not like. 20:42:29 ...if you keep changing requirements it looks more and more like it needs a new property on the keys 20:43:12 ... user ID or cred blob is not something I want to change 20:43:46 ...I don't want to tangle with first party 20:44:13 jbradley: the name space does not let third party SPC cred used for normal WebAuthn authentication 20:44:24 akshay: I do not see that solution right now 20:45:17 jbradley: could do name space thing, but if you want to use SpC for cred in first party context, then we need to do something different in name space 20:45:49 ...if we separate the SPC cred, so it is not used for normal authentication, they may ned two name spaces 20:46:03 akshay: they have their own server logic 20:47:28 jbradely: I will look at it to see what we can do, but some of the browser may have to change 20:48:02 jeffH: it could be a client extension and not pass down to authenticator 20:48:11 akshay: thinking that with SPC 20:49:56 jbradley: maybe we never mix SPC context 20:54:35 agl: I want to talk about JSON 20:55:03 Martin: Issue1683 20:55:49 ...want JSON serialized - all the RPs have to write their own serialization 20:56:03 ...shold we make RPs lives easier? akshay: if it helps RPs i am favor of this 20:56:49 tony: does not seem to break anything. 20:56:59 martin: it is backward compatible. 20:57:11 ...default case for simple RP 20:57:14 tony: is there support 20:57:18 ...agl? 20:57:21 agl: yes 20:57:38 dan: I would want to support this 20:58:07 ...I would support in mozilla at some time later 20:58:42 agl: JSON here would not unpack authn data . 20:58:51 ...would turn into strings 