 Chromium Code Reviews
 Chromium Code Reviews Issue 1136473006:
  Don't autofill credit cards on non-secure pages  (Closed) 
  Base URL: https://chromium.googlesource.com/chromium/src.git@master
    
  
    Issue 1136473006:
  Don't autofill credit cards on non-secure pages  (Closed) 
  Base URL: https://chromium.googlesource.com/chromium/src.git@master| Index: components/autofill/core/browser/autofill_client.h | 
| diff --git a/components/autofill/core/browser/autofill_client.h b/components/autofill/core/browser/autofill_client.h | 
| index 6d2edcab3db9f361f4383d63bb7b4556b46d6cb3..8fb749f81696300c9c61634f7592d5eee97ebeb7 100644 | 
| --- a/components/autofill/core/browser/autofill_client.h | 
| +++ b/components/autofill/core/browser/autofill_client.h | 
| @@ -12,6 +12,7 @@ | 
| #include "base/memory/weak_ptr.h" | 
| #include "base/strings/string16.h" | 
| #include "ui/base/window_open_disposition.h" | 
| +#include "url/gurl.h" | 
| class IdentityProvider; | 
| @@ -173,6 +174,13 @@ class AutofillClient { | 
| // Opens |url| with the supplied |disposition|. | 
| virtual void LinkClicked(const GURL& url, | 
| WindowOpenDisposition disposition) = 0; | 
| + | 
| + // If the context is secure. Default implementation only checks the | 
| + // |form_origin|'s scheme being cryptographic, override in inherited classes | 
| + // to also check for secure https and no mixed content. | 
| + virtual bool IsContextSecure(const GURL& form_origin) { | 
| + return form_origin.SchemeIsCryptographic(); | 
| 
jww
2015/06/08 18:37:35
As per the comment in gurl.h, we should almost nev
 
sigbjorn
2015/06/12 11:47:53
This is the fallback mechanism. Autofill_manager w
 | 
| + }; | 
| }; | 
| } // namespace autofill |