New issue
Advanced search Search tips

Issue 700960 link

Starred by 3 users

Issue metadata

Status: Fixed
Owner:
Closed: Mar 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 3
Type: Bug



Sign in to add a comment

[Password Manager] Keep passwords out as renderer if possible

Project Member Reported by dvadym@chromium.org, Mar 13 2017

Issue description

When credentials are going to be filled, the only password that's required to be in a renderer immediately is that one that's going to be autofilled. Thus in case of fill on account select we can clear all passwords before sending to the renderer, in case of autofilling we can clear all passwords except that one that will be autofilled.
 
Project Member

Comment 1 by bugdroid1@chromium.org, Mar 13 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/bb38ea3085965823c24ac636a2d560631448c18d

commit bb38ea3085965823c24ac636a2d560631448c18d
Author: dvadym <dvadym@chromium.org>
Date: Mon Mar 13 18:12:33 2017

Clear password values before sending them to the renderer process.

All passwords for additional logins are cleared (that are passwords for non-preferred accounts, that possible to be filled on account select). In case of account select filling the password to the preferred account is also cleared.

BUG= 700960 

Review-Url: https://codereview.chromium.org/2736393003
Cr-Commit-Position: refs/heads/master@{#456428}

[modify] https://crrev.com/bb38ea3085965823c24ac636a2d560631448c18d/components/autofill/core/common/password_form_fill_data.cc
[modify] https://crrev.com/bb38ea3085965823c24ac636a2d560631448c18d/components/autofill/core/common/password_form_fill_data.h
[modify] https://crrev.com/bb38ea3085965823c24ac636a2d560631448c18d/components/password_manager/content/browser/content_password_manager_driver.cc
[modify] https://crrev.com/bb38ea3085965823c24ac636a2d560631448c18d/components/password_manager/content/browser/content_password_manager_driver_unittest.cc

Comment 2 by dvadym@chromium.org, Mar 17 2017

Status: Fixed (was: Started)

Sign in to add a comment