[story] [android] Implement a Trusted Payment Experience

NEW
Unassigned

Status

Tracking
User Story
5 years ago
2 years ago

People

(Reporter: dbialer, Unassigned)

Tracking

(Blocks: 1 bug, {uiwanted})

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: u=con c=id p=, URL)

User Story

PayAndID-150		As a user, I would like to be informed when I am in a payments or identity experience so that I can be assured that my identity will be protected and payments are secure with a "trusted payment container" (not to be taken as implementation specific like B2G TrustedUI).

PayAndID-151		As a user I should be able to initiate a trusted payment experience inside an app so that I can be assured that my identity will be protected and payments are secure with a "trusted payment container".

PayAndID-152		As a user I should be able to cancel a trusted payment experience (and any/all the processes started inside it) so that I can abort a process and return to what I was doing.

PayAndID-153		As a user I should be able to switch from 1 app with trusted payment experience to another using the Task Manager. The trusted payment experience should reappear when coming back to the app so I am confident the process is consistent and secure.

PayAndID-154		As a user I should be able to reopen an app with an unfinished trusted payment experience process, and the trusted payment experience dialog should reappear so I am confident the process is consistent and secure

PayAndID-155		As a user I should be able to lock-unlock the phone during a trusted payment experience process so I can leave what I am doing and return to it, still confident the process is consistent and secure

PayAndID-156		As a user I should be able to receive a call while executing a trusted payment experience so I am able to switch applications on my phone and "pause" the secure process and return to it

PayAndID-157		As a user I should be able to receive a notification while executing a trusted payment experience so I am able to switch applications on my phone and "pause" the secure process and return to it
(Reporter)

Description

5 years ago
This is like the trustedUI, but for Android.


PayAndID-150		As a user, I would like to be informed when I am in a payments or identity experience so that I can be assured that my identity will be protected and payments are secure with a "trusted payment container" (not to be taken as implementation specific like B2G TrustedUI).

PayAndID-151		As a user I should be able to initiate a trusted payment experience inside an app so that I can be assured that my identity will be protected and payments are secure with a "trusted payment container".

PayAndID-152		As a user I should be able to cancel a trusted payment experience (and any/all the processes started inside it) so that I can abort a process and return to what I was doing.

PayAndID-153		As a user I should be able to switch from 1 app with trusted payment experience to another using the Task Manager. The trusted payment experience should reappear when coming back to the app so I am confident the process is consistent and secure.

PayAndID-154		As a user I should be able to reopen an app with an unfinished trusted payment experience process, and the trusted payment experience dialog should reappear so I am confident the process is consistent and secure

PayAndID-155		As a user I should be able to lock-unlock the phone during a trusted payment experience process so I can leave what I am doing and return to it, still confident the process is consistent and secure

PayAndID-156		As a user I should be able to receive a call while executing a trusted payment experience so I am able to switch applications on my phone and "pause" the secure process and return to it

PayAndID-157		As a user I should be able to receive a notification while executing a trusted payment experience so I am able to switch applications on my phone and "pause" the secure process and return to it

Updated

5 years ago
User Story: (updated)

Comment 1

4 years ago
I heard a vague rumour that trusted ui is going away in Firefox OS. We'd need to know what this looks like and where it would be done, platform, web?
Keywords: uiwanted

Comment 2

2 years ago
Another way to the same (similar) goal:
https://github.com/w3c/websec/issues/91#issuecomment-235160950

Bad Mozilla attempt:
https://bugzilla.mozilla.org/show_bug.cgi?id=1267362#c7
You need to log in before you can comment on or make changes to this bug.