New issue
Advanced search Search tips

Issue 766302 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Nov 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 1
Type: Bug



Sign in to add a comment
This issue has been classified as spam. Please report incorrect spam classification.

[WebView Autofill] remove form action check.

Project Member Reported by michaelbai@chromium.org, Sep 18 2017

Issue description

Remove form action check because we get some cases that uses javascript in action, it is hard to check whether the action is secure.

see b/65561733

 

Comment 1 by torne@chromium.org, Sep 18 2017

What's chrome's behaviour around this? Does it allow any action? It seems like we do at least know that HTTP actions aren't secure..
Project Member

Comment 2 by bugdroid1@chromium.org, Sep 19 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/6b032dd483f18e0389fbde563a26cf32dcf62f1d

commit 6b032dd483f18e0389fbde563a26cf32dcf62f1d
Author: Tao Bai <michaelbai@chromium.org>
Date: Tue Sep 19 18:44:07 2017

[WebView autofill] Remove form action check.

Remove form action check, only requres secure origin to trigger
autofill query for WebView.

Bug:  766302 
Change-Id: I416a174904fe7b2adc16226d1b68fa94056a9ee5
Reviewed-on: https://chromium-review.googlesource.com/671803
Reviewed-by: Emily Stark <estark@chromium.org>
Reviewed-by: Roger McFarlane <rogerm@chromium.org>
Commit-Queue: Tao Bai <michaelbai@chromium.org>
Cr-Commit-Position: refs/heads/master@{#502901}
[modify] https://crrev.com/6b032dd483f18e0389fbde563a26cf32dcf62f1d/components/autofill/content/renderer/autofill_agent.cc

Labels: -Pri-3 Merge-Request-62 M-62 Pri-1
Status: Assigned (was: Untriaged)

Comment 4 by cma...@chromium.org, Sep 21 2017

Labels: -Merge-Request-62 Merge-Approved-62
Merge approved upon verification of the fix on trunk and branch 3202.
Project Member

Comment 5 by bugdroid1@chromium.org, Sep 22 2017

Labels: -merge-approved-62 merge-merged-3202
The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/e91f55bbd9cbedf400553b9e3eb2c854807bf684

commit e91f55bbd9cbedf400553b9e3eb2c854807bf684
Author: Tao Bai <michaelbai@chromium.org>
Date: Fri Sep 22 00:33:35 2017

[WebView autofill] Remove form action check.

Remove form action check, only requres secure origin to trigger
autofill query for WebView.

Bug:  766302 
Change-Id: I416a174904fe7b2adc16226d1b68fa94056a9ee5
Reviewed-on: https://chromium-review.googlesource.com/671803
Reviewed-by: Emily Stark <estark@chromium.org>
Reviewed-by: Roger McFarlane <rogerm@chromium.org>
Commit-Queue: Tao Bai <michaelbai@chromium.org>
Cr-Original-Commit-Position: refs/heads/master@{#502901}(cherry picked from commit 6b032dd483f18e0389fbde563a26cf32dcf62f1d)
Reviewed-on: https://chromium-review.googlesource.com/677641
Reviewed-by: Tao Bai <michaelbai@chromium.org>
Cr-Commit-Position: refs/branch-heads/3202@{#386}
Cr-Branched-From: fa6a5d87adff761bc16afc5498c3f5944c1daa68-refs/heads/master@{#499098}
[modify] https://crrev.com/e91f55bbd9cbedf400553b9e3eb2c854807bf684/components/autofill/content/renderer/autofill_agent.cc

Status: Fixed (was: Assigned)

Sign in to add a comment