[wpt-sync] Sync PR 16775 - [sms] Restrict SMS Receiver API to Top Level Frames
Categories
(Testing :: web-platform-tests, defect, P4)
Tracking
(firefox69 fixed)
| Tracking | Status | |
|---|---|---|
| firefox69 | --- | fixed |
People
(Reporter: wpt-sync, Unassigned)
References
()
Details
(Whiteboard: [wptsync downstream])
Sync web-platform-tests PR 16775 into mozilla-central (this bug is closed when the sync is complete).
PR: https://github.com/web-platform-tests/wpt/pull/16775
Details from upstream follow.
Ayu Ishii <ayui@chromium.org> wrote:
[sms] Restrict SMS Receiver API to Top Level Frames
This change restrictes the SMS Receiver API to only be used from top level
frames to prevent malicious sites from accessing the one time passcodes
for signup. Restriction in the browser process will be added in a
following CL.Bug: 955765
Change-Id: Ie11e3b1fc6c9bf4597bde880d5083fec7255b79a
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/1594211
Reviewed-by: Reilly Grant \<reillyg@chromium.org>
Commit-Queue: Ayu Ishii \<ayui@chromium.org>
Cr-Commit-Position: refs/heads/master@{#658694}
| Assignee | ||
Comment 1•6 years ago
|
||
| Assignee | ||
Comment 2•6 years ago
|
||
| Assignee | ||
Comment 3•6 years ago
|
||
| Assignee | ||
Comment 4•6 years ago
|
||
Comment 6•6 years ago
|
||
| bugherder | ||
Description
•