You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to FIDO Dev (fido-dev)
Hi Team,
If example.com is selected as the common RP ID, all other domains—such as example.in, example.eu, and example.au—will make cross-origin requests to the .well-known URL hosted on example.com.
Could this cross-domain API call raise any compliance concerns (e.g., GDPR or other regional data protection regulations)?
Tim Cappalli
unread,
Jul 11, 2025, 5:52:01 AMJul 11
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to hetin k, FIDO Dev (fido-dev)
That is something your legal / compliance team should determine for your organization before utilizing the capability.
If example.com is selected as the common RP ID, all other domains—such as example.in, example.eu, and example.au—will make cross-origin requests to the .well-known URL hosted on example.com.
Could this cross-domain API call raise any compliance concerns (e.g., GDPR or other regional data protection regulations)?