Intent to Implement: Reject PaymentRequest.show with SecurityError DOMException if it is not triggered by user activation

87 views
Skip to first unread message

Ganggui Tang

unread,
Mar 26, 2018, 10:52:37 AM3/26/18
to blin...@chromium.org, PaymentRequest
goge...@chromium.orgrou...@chromium.org
https://www.w3.org/TR/payment-request/#show-method Allow PaymentRequest.show can be triggered without user activation could be abused by malicious websites. To protect users, the spec has been changed to require user activation.
Protect users from unintended PaymentRequest.show.
Firefox: In development Edge: No public signals Safari: Shipped Web developers: No signals
This may require web developers change their implementations.
None
Yes https://crbug.com/825270 https://www.chromestatus.com/features/5948593429020672
No

Reply all
Reply to author
Forward
0 new messages