New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 733036 link

Starred by 0 users

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

Refactor the CredentialManagement API mojo and dispatch logic

Project Member Reported by kpaulhamus@chromium.org, Jun 14 2017

Issue description

Extract the disambiguation logic from //components/password_manager into
an intermediary layer in the browser that picks the backend and sends off
requests to the password store or the webauthn layer. Refactor the WebAuthN mojo pipe into the CredentialManager mojo pipe.

 
Components: Blink>WebAuthentication
Cc: engedy@chromium.org

Comment 3 by engedy@chromium.org, Mar 31 2018

Labels: M-69 Pri-3 Type-Bug-Security
This is related to Issue 762638, as it revolves around the question of how the architecture between //device/fido, //services, Blink, and //components/password_manager should ideally look like.
Do we really need to keep this in the security queue. Might Restrict-View-Google be sufficient?
If it needs to be in the security queue, we'll have to figure out some mandatory labels, such as:
- Severity: https://www.chromium.org/developers/severity-guidelines
- Impact: Stable / Beta / Head / None
- OS'es that are affected

+ we also need to have an owner assigned.

Please advise whether we make it a regular bug with Restrict-View-Google label, or provide a guidance on the points listed above. Thanks!
Labels: -Type-Bug-Security Type-Bug
This is a harmless refactoring, no need to put any restrictions on it. Sorry, I must have mis-clicked when triaging it.
Labels: -M-69
Owner: kpaulhamus@chromium.org
Status: Assigned (was: Available)

Sign in to add a comment