| Index: content/child/webcrypto/openssl/ec_key_openssl.cc
|
| diff --git a/content/child/webcrypto/openssl/ec_key_openssl.cc b/content/child/webcrypto/openssl/ec_key_openssl.cc
|
| index 81e233701f42767301e104023301db12f4942f6f..fe2be17c28d178d259b527ae6fc6db85c0fe2976 100644
|
| --- a/content/child/webcrypto/openssl/ec_key_openssl.cc
|
| +++ b/content/child/webcrypto/openssl/ec_key_openssl.cc
|
| @@ -283,17 +283,22 @@ Status EcAlgorithm::GenerateKey(const blink::WebCryptoAlgorithm& algorithm,
|
| Status EcAlgorithm::VerifyKeyUsagesBeforeImportKey(
|
| blink::WebCryptoKeyFormat format,
|
| blink::WebCryptoKeyUsageMask usages) const {
|
| + bool checkEmptyUsage = true;
|
| switch (format) {
|
| case blink::WebCryptoKeyFormatSpki:
|
| - return CheckKeyCreationUsages(all_public_key_usages_, usages);
|
| + return CheckKeyCreationUsages(all_public_key_usages_, usages,
|
| + checkEmptyUsage);
|
| case blink::WebCryptoKeyFormatPkcs8:
|
| - return CheckKeyCreationUsages(all_private_key_usages_, usages);
|
| + return CheckKeyCreationUsages(all_private_key_usages_, usages,
|
| + checkEmptyUsage);
|
| case blink::WebCryptoKeyFormatJwk:
|
| // The JWK could represent either a public key or private key. The usages
|
| // must make sense for one of the two. The usages will be checked again by
|
| // ImportKeyJwk() once the key type has been determined.
|
| - if (CheckKeyCreationUsages(all_private_key_usages_, usages).IsSuccess() ||
|
| - CheckKeyCreationUsages(all_public_key_usages_, usages).IsSuccess()) {
|
| + if (CheckKeyCreationUsages(all_private_key_usages_, usages,
|
| + checkEmptyUsage).IsSuccess() ||
|
| + CheckKeyCreationUsages(all_public_key_usages_, usages,
|
| + checkEmptyUsage).IsSuccess()) {
|
| return Status::Success();
|
| }
|
| return Status::ErrorCreateKeyBadUsages();
|
|
|