Implement defensive limits on the size of Payment Request API inputs |
||||
Issue descriptionPerformance problems or degenerate UI cases could be caused by excessively large inputs from malicious or malfunctioning pages. To protect against this, we should limit the size of all variable-length inputs (methodData, supportedMethods, shippingOptions, etc.) that we're willing to handle. This limit should be high so as to not preclude any possible practical use.
,
Jun 6 2017
,
Jun 8 2017
Already implemented in Android. Still need for iOS.
,
Jun 27 2017
|
||||
►
Sign in to add a comment |
||||
Comment 1 by rouslan@chromium.org
, Aug 31 2016Owner: rouslan@chromium.org
Status: Assigned (was: Untriaged)