content/browser/webauth: allow credProtect level two for non-resident keys.
If `requireResidentKey` is false an authenticator may, at least with CTAP 2.0, still create a resident key. RPs might want to set credProtect level two for that case even though it's moot for non-resident keys. This change allows that stance. Bug: 941120 Change-Id: If4be7aabbb2d5b002942a0dc033f49b4c71b8538 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/1595972 Auto-Submit: Adam Langley <agl@chromium.org> Reviewed-by:Martin Kreichgauer <martinkr@google.com> Commit-Queue: Adam Langley <agl@chromium.org> Cr-Commit-Position: refs/heads/master@{#657458}
Showing
Please register or sign in to comment