Hi Group,
Wondering if anyone has an answer for this or if anyone has experimented with this setup.
Setup
1. I have two domains a.com and b.com and an iOS app App_C 2. b.com/.well-known/apple-app-site-association lists
App_C so App_C can use passkey from b.com
Question
1. Can
App_C uses passkey from
a.com with the current setup?
2. If the answer is no, then setup
a.com/.well-known/apple-app-site-association to include
App_C should now allow
App_C to to use passkey from
a.com, but can
App_C uses
a.com passkey while visiting
b.com (taking advantage of related origins) in embedded browser?
Any clarification on RP ID binding rules between native apps and web origins would be greatly appreciated!
Thanks,
Jack