Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add examples for PRF extension #2088

Closed
akshayku opened this issue Jun 26, 2024 · 4 comments · Fixed by #2174
Closed

Add examples for PRF extension #2088

akshayku opened this issue Jun 26, 2024 · 4 comments · Fixed by #2174
Assignees
Labels
@Risk Items that are at risk for L3 stat:pr-open type:editorial

Comments

@akshayku
Copy link
Contributor

Proposed Change

Multiple people who are implementing PRF extensions have got the implementation wrong regarding extension fields in request and response.

We have to add some examples for this extension.

@akshayku akshayku self-assigned this Jun 26, 2024
@MasterKale
Copy link
Contributor

I've got a sample prf tester HTML doc in a gist that has seemed to survive scrutiny so far (or maybe it's the reason why people are doing prf incorrectly 😅)

https://gist.github.com/MasterKale/dbe39a01438251f0cbd55576304731fd

Anything in here we might want to borrow? That said there are plenty of footguns with prf and so if we do include examples we should include plenty of disclaimers that e.g. deleting a passkey permanently prevents access to anything protected by that passkey's corresponding PRF bytes.

@nadalin nadalin added the @Risk Items that are at risk for L3 label Jul 17, 2024
@emlun
Copy link
Member

emlun commented Jul 17, 2024

Related:

@nadalin nadalin removed the @Risk Items that are at risk for L3 label Jul 17, 2024
@MasterKale
Copy link
Contributor

From WG Meeting @ 7/17: Examples of using PRF seem more applicable as either test vectors or as externally produced documentation. Let's bucket this as something to address as part of #1633.

@nadalin
Copy link
Contributor

nadalin commented Aug 14, 2024

@akshayku Need PR open

@nadalin nadalin added this to the L3-WD-02 milestone Aug 14, 2024
@nadalin nadalin assigned emlun and unassigned akshayku Aug 14, 2024
@nadalin nadalin added the @Risk Items that are at risk for L3 label Aug 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
@Risk Items that are at risk for L3 stat:pr-open type:editorial
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants