Currently, the PasswordAccessoryController collects to every credential that is passed into |OnPasswordsAvailable| and ignores the origin.
This means, we show filling credentials for iframes in the Password accessory of the embedding site.
example:
- site a.com embeds an iframe with site b.com
- all credential of b.com are shown as suggestions for site a.com
==> This simplifies reuse of b.com's credentials on a.com
Comment 1 by bugdroid1@chromium.org
, Jun 22 2018