Maybe Passwords Are the Future
kevincox.ca
kevincox.ca
I too believe passwords will have their role in the future - although I'd love to see their roles swapped: WebAuthn as first authentication factor - passwords as the optional MFA.
I've pushed a fix.
If you can find a way to abuse a valid authentication to one site in order to gain access to another site, that sounds like a very firmly valid security issue needing investigated.