Allowlist Gaia origin for privileged chrome Javascript API
The code is still behind a feature toggle and not fully implemented. Follow-up patches will introduce interactions with the browser process via Mojo. Independently of the browser process enforcing security origin checks, the Javascript API itself should also be exposed only to the Gaia origin. Bug: 1000146 Change-Id: Ib95bf8e66db6643352c92939d7c3444fe0231247 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/1813304Reviewed-by:David Roger <droger@chromium.org> Commit-Queue: Mikel Astiz <mastiz@chromium.org> Cr-Commit-Position: refs/heads/master@{#698423}
Showing
Please register or sign in to comment