Don't allow passing the raw notification ID to close persistent notifications |
|||
Issue descriptionInstead we should use an unguessable token string like non-persistent notifications already do, from which the notification ID is re-calculated using the trusted origin (to prevent origins closing other origins' notifications in case of a compromised renderer).
,
Aug 1
,
Nov 21
***Mass UI Triage*** |
|||
►
Sign in to add a comment |
|||
Comment 1 by awdf@chromium.org
, Aug 1