1

Steps to reproduce the problem:

  1. Open up Chrome on a computer and go to https://webauthn.io .
  2. Enter a random username and click Register.
  3. Choose "Use a different phone or tablet".
  4. Scan the QR code using an Android device.
  5. Then, click on the link that looks like FIDO:/xxxxxxxxxx on the Android device.
  6. On the Android device that was used to scan the QR code, click on the "Connect devices" button.
  7. When the text "Create a passkey" appears on the Android device, click on Continue.
  8. Unfocus the https://webauthn.io page on the computer (do not close the page).
  9. Create a passkey using the mobile device's screen lock.
  10. Navigate back to the same https://webauthn.io tab on the computer.

You should be able to see the message:

"The operation is not allowed at this time because the page does not have focus."

However, Google password manager still creates a passkey for https://webauthn.io. Why is that the case?

0