New issue
Advanced search Search tips

Issue 688461 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Feb 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 2
Type: Bug



Sign in to add a comment

Credit card AutoFill offers to scan credit card to autofill nonsecure form

Project Member Reported by elawrence@chromium.org, Feb 3 2017

Issue description

Chrome Version: 58.0.3000.3
OS: Android

What steps will reproduce the problem?
(1) Visit http://webdbg.com/test/forms/creditcard.asp
(2) Touch to enter the Credit Card number field

Observe: "Payment Not Secure. Autofill disabled." warnings appear; then, in seeming contradiction, "Scan credit card" appears below. If you choose to scan a card, the form auto-fills.

AutofillManager::ShouldShowScanCreditCard should probably check the security state of the form before offering this option?
 

Comment 1 by ma...@chromium.org, Feb 3 2017

sgtm! Thanks for checking
PaymentNotSecureScanAnyway.png.png
56.4 KB View Download
Owner: elawrence@chromium.org
Status: Started (was: Untriaged)
Project Member

Comment 4 by bugdroid1@chromium.org, Feb 8 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/a0cab13ed385f0c524f29e279b2874677872bcdf

commit a0cab13ed385f0c524f29e279b2874677872bcdf
Author: elawrence <elawrence@chromium.org>
Date: Wed Feb 08 02:40:59 2017

Do not show Scan or Sign In options when credit card form is non-secure

Credit card autofill logic may offer "Scan credit card" and "Sign in to
Chrome to use cards from your Google account" options when filling out
a credit card form.

These options should not be shown when the form is not secure. We
instead notify users that non-secure forms will not autofill.

BUG= 688461 

Review-Url: https://codereview.chromium.org/2676513007
Cr-Commit-Position: refs/heads/master@{#448870}

[modify] https://crrev.com/a0cab13ed385f0c524f29e279b2874677872bcdf/components/autofill/core/browser/autofill_manager.cc
[modify] https://crrev.com/a0cab13ed385f0c524f29e279b2874677872bcdf/components/autofill/core/browser/autofill_manager.h
[modify] https://crrev.com/a0cab13ed385f0c524f29e279b2874677872bcdf/components/autofill/core/browser/autofill_manager_unittest.cc

Status: Fixed (was: Started)

Sign in to add a comment