W3C

SPC Task Force

04 October 2021

Attendees

Present
Anne Pouillard (Worldline), Ian Jacobs (W3C), John Bradley (Yubico), Stephen McGruer (Google), Susan Pandy (Discover), Werner Bruinings (American Express)
Regrets
-
Chair
Ian
Scribe
Ian

Meeting minutes

Preparing for remote meeting

https://github.com/w3c/webpayments/wiki/Agenda-TPAC2021

What topics to bring forward?

John: WebAuthn has competing opinions on cross-origin.
… what is the mechanism by which the relying party mints a credential so that it may later be used cross-origin.
… what we have now is suitable for an experiment but is probably not the right long-term solution
… at least being able to use these cross-origin credentials cross-browser.
… also enabling these credentials on roaming authenticators would be good

https://github.com/w3c/secure-payment-confirmation/issues

For issue 128, one question is whether user activation required for FIDO/SPC on registration

John: Is this user activation coming from a particular browser behavior?

Stephen: The concern with cross-origin credential is for any iframe creating a tracking credential
… just because it can come from an iframe it's not unreasonable to request a user activation

John: SPC doesn't specifically deal with cross-origin create; that's a webauthn thing

Stephen: But SPC does allow cross-origin create (on Chrome)

[Discussion of WebAuthn cross-origin registration in iframe]

Next meeting

18 October

Minutes manually created (not a transcript), formatted by scribe.perl version 136 (Thu May 27 13:50:24 2021 UTC).