Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(556)

Issue 1928323002: CREDENTIAL: Tighten the behavior of 'requireUserMediation()' (Closed)

Created:
4 years, 7 months ago by Mike West
Modified:
4 years, 7 months ago
Reviewers:
vabr (Chromium)
CC:
chromium-reviews, darin-cc_chromium.org, gcasto+watchlist_chromium.org, jam, mkwst+watchlist-passwords_chromium.org, vabr+watchlistpasswordmanager_chromium.org
Base URL:
https://chromium.googlesource.com/chromium/src.git@master
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

CREDENTIAL: Tighten the behavior of 'requireUserMediation()' Currently, we're looking for an exact origin match between a stored PasswordForm and the page which called 'requireUserMediation()'. We ought to be looking for a match between their registrable domains, given that we allow credentials to flow ~freely between these origins. This patch tightens the check accordingly. BUG=607858 R=vabr@chromium.org Committed: https://crrev.com/3aa4344859e35071117a4278663eecf4f3ea9d17 Cr-Commit-Position: refs/heads/master@{#390618}

Patch Set 1 #

Unified diffs Side-by-side diffs Delta from patch set Stats (+31 lines, -6 lines) Patch
M components/password_manager/content/browser/credential_manager_impl_unittest.cc View 4 chunks +16 lines, -2 lines 0 comments Download
M components/password_manager/core/browser/credential_manager_pending_require_user_mediation_task.h View 1 chunk +1 line, -1 line 0 comments Download
M components/password_manager/core/browser/credential_manager_pending_require_user_mediation_task.cc View 3 chunks +14 lines, -3 lines 0 comments Download

Messages

Total messages: 9 (2 generated)
Mike West
vabr@, WDYT?
4 years, 7 months ago (2016-04-29 10:03:04 UTC) #1
vabr (Chromium)
LGTM! Just curious why this is "tightening" the check as opposed to loosening it (more ...
4 years, 7 months ago (2016-04-29 11:27:42 UTC) #2
Mike West
On 2016/04/29 at 11:27:42, vabr wrote: > LGTM! > > Just curious why this is ...
4 years, 7 months ago (2016-04-29 11:32:06 UTC) #3
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/patch-status/1928323002/1 View timeline at https://chromium-cq-status.appspot.com/patch-timeline/1928323002/1
4 years, 7 months ago (2016-04-29 11:32:17 UTC) #5
commit-bot: I haz the power
Committed patchset #1 (id:1)
4 years, 7 months ago (2016-04-29 11:36:50 UTC) #6
vabr (Chromium)
On 2016/04/29 11:32:06, Mike West (slow until 25th) wrote: > On 2016/04/29 at 11:27:42, vabr ...
4 years, 7 months ago (2016-04-29 11:40:49 UTC) #7
commit-bot: I haz the power
4 years, 7 months ago (2016-04-30 17:25:01 UTC) #8
Message was sent while issue was closed.
Patchset 1 (id:??) landed as
https://crrev.com/3aa4344859e35071117a4278663eecf4f3ea9d17
Cr-Commit-Position: refs/heads/master@{#390618}

Powered by Google App Engine
This is Rietveld 408576698