You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In Nextcloud, logins via WebAuthn are single-factor authentications and not two-factor authentications. In #41 and #69 UserVerification was set to DISCOURAGED with the reasoning that the WebAuthn authentication is used after a login authentication. However, this reasoning is wrong because when enabling and configuring WebAuthn it is used instead of a password login and not after a password login. The best practice, also recommended by WebAuthn, is to set UserVerification to Preferred and it should be applied here too. Hence, I suggest to revert #69 .
The text was updated successfully, but these errors were encountered:
In Nextcloud, logins via WebAuthn are single-factor authentications and not two-factor authentications. In #41 and #69 UserVerification was set to DISCOURAGED with the reasoning that the WebAuthn authentication is used after a login authentication. However, this reasoning is wrong because when enabling and configuring WebAuthn it is used instead of a password login and not after a password login. The best practice, also recommended by WebAuthn, is to set UserVerification to Preferred and it should be applied here too. Hence, I suggest to revert #69 .
The text was updated successfully, but these errors were encountered: