[FedCM] Fix Set-Login same-site bypass in SXG cert fetches [chromium/src : main]

0 views
Skip to first unread message

Christian Biesinger (Gerrit)

unread,
Apr 28, 2026, 5:30:00 PM (23 hours ago) Apr 28
to Christian Biesinger, Nicolás Peña, Chromium LUCI CQ, chromium...@chromium.org, Peter Beverloo, headless...@chromium.org, loading...@chromium.org
Attention needed from Nicolás Peña

New activity on the change

Open in Gerrit

Related details

Attention is currently required from:
  • Nicolás Peña
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement is not satisfiedCode-Owners
  • requirement is not satisfiedCode-Review
  • requirement is not satisfiedReview-Enforcement
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I55b637a784e0727c251db0202f02d975c349f961
Gerrit-Change-Number: 7800003
Gerrit-PatchSet: 2
Gerrit-Owner: Christian Biesinger <cbies...@chromium.org>
Gerrit-Reviewer: Christian Biesinger <cbies...@chromium.org>
Gerrit-Reviewer: Nicolás Peña <n...@chromium.org>
Gerrit-CC: Peter Beverloo <pe...@chromium.org>
Gerrit-Attention: Nicolás Peña <n...@chromium.org>
Gerrit-Comment-Date: Tue, 28 Apr 2026 21:29:51 +0000
Gerrit-HasComments: No
Gerrit-Has-Labels: No
satisfied_requirement
unsatisfied_requirement
open
diffy

Nicolás Peña (Gerrit)

unread,
10:48 AM (5 hours ago) 10:48 AM
to Christian Biesinger, Chromium LUCI CQ, chromium...@chromium.org, Peter Beverloo, headless...@chromium.org, loading...@chromium.org
Attention needed from Christian Biesinger

Nicolás Peña voted and added 2 comments

Votes added by Nicolás Peña

Code-Review+1

2 comments

File content/common/webid/identity_url_loader_throttle.cc
Line 47, Patchset 4 (Latest):void IdentityUrlLoaderThrottle::DetachFromCurrentSequence() {
Nicolás Peña . unresolved

What is this method for? Its confusing. Can we add a comment?

File content/common/webid/identity_url_loader_throttle_unittest.cc
Line 44, Patchset 4 (Latest): network::mojom::RequestDestination cb_destination_;
Nicolás Peña . unresolved

It's better to initialize this member to a default value (e.g., `network::mojom::RequestDestination::kEmpty`) to avoid potential garbage reads if a test checks it before any callback is run.

Open in Gerrit

Related details

Attention is currently required from:
  • Christian Biesinger
Submit Requirements:
    • requirement satisfiedCode-Coverage
    • requirement is not satisfiedCode-Owners
    • requirement satisfiedCode-Review
    • requirement is not satisfiedNo-Unresolved-Comments
    • requirement satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: I55b637a784e0727c251db0202f02d975c349f961
    Gerrit-Change-Number: 7800003
    Gerrit-PatchSet: 4
    Gerrit-Owner: Christian Biesinger <cbies...@chromium.org>
    Gerrit-Reviewer: Christian Biesinger <cbies...@chromium.org>
    Gerrit-Reviewer: Nicolás Peña <n...@chromium.org>
    Gerrit-CC: Peter Beverloo <pe...@chromium.org>
    Gerrit-Attention: Christian Biesinger <cbies...@chromium.org>
    Gerrit-Comment-Date: Wed, 29 Apr 2026 14:48:09 +0000
    Gerrit-HasComments: Yes
    Gerrit-Has-Labels: Yes
    satisfied_requirement
    unsatisfied_requirement
    open
    diffy

    Christian Biesinger (Gerrit)

    unread,
    11:30 AM (5 hours ago) 11:30 AM
    to Christian Biesinger, Nicolás Peña, Chromium LUCI CQ, chromium...@chromium.org, Peter Beverloo, headless...@chromium.org, loading...@chromium.org

    Christian Biesinger added 1 comment

    Patchset-level comments
    File-level comment, Patchset 4 (Latest):
    Christian Biesinger . resolved

    I made an alternative fix for this in https://chromium-review.googlesource.com/c/chromium/src/+/7803097... let me know which you prefer

    (Will add that comment either way, although it's unrelated to this change)

    Open in Gerrit

    Related details

    Attention set is empty
    Submit Requirements:
    • requirement satisfiedCode-Coverage
    • requirement is not satisfiedCode-Owners
    • requirement satisfiedCode-Review
    • requirement is not satisfiedNo-Unresolved-Comments
    • requirement satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: I55b637a784e0727c251db0202f02d975c349f961
    Gerrit-Change-Number: 7800003
    Gerrit-PatchSet: 4
    Gerrit-Owner: Christian Biesinger <cbies...@chromium.org>
    Gerrit-Reviewer: Christian Biesinger <cbies...@chromium.org>
    Gerrit-Reviewer: Nicolás Peña <n...@chromium.org>
    Gerrit-CC: Peter Beverloo <pe...@chromium.org>
    Gerrit-Comment-Date: Wed, 29 Apr 2026 15:30:03 +0000
    Gerrit-HasComments: Yes
    Gerrit-Has-Labels: No
    satisfied_requirement
    unsatisfied_requirement
    open
    diffy

    Christian Biesinger (Gerrit)

    unread,
    12:58 PM (3 hours ago) 12:58 PM
    to Christian Biesinger, Nicolás Peña, Chromium LUCI CQ, chromium...@chromium.org, Peter Beverloo, headless...@chromium.org, loading...@chromium.org

    Christian Biesinger added 2 comments

    File content/common/webid/identity_url_loader_throttle.cc
    Line 47, Patchset 4:void IdentityUrlLoaderThrottle::DetachFromCurrentSequence() {
    Nicolás Peña . resolved

    What is this method for? Its confusing. Can we add a comment?

    Christian Biesinger
    File content/common/webid/identity_url_loader_throttle_unittest.cc
    Line 44, Patchset 4: network::mojom::RequestDestination cb_destination_;
    Nicolás Peña . resolved

    It's better to initialize this member to a default value (e.g., `network::mojom::RequestDestination::kEmpty`) to avoid potential garbage reads if a test checks it before any callback is run.

    Christian Biesinger

    Done

    Open in Gerrit

    Related details

    Attention set is empty
    Submit Requirements:
      • requirement satisfiedCode-Coverage
      • requirement is not satisfiedCode-Owners
      • requirement satisfiedCode-Review
      • requirement satisfiedReview-Enforcement
      Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
      Gerrit-MessageType: comment
      Gerrit-Project: chromium/src
      Gerrit-Branch: main
      Gerrit-Change-Id: I55b637a784e0727c251db0202f02d975c349f961
      Gerrit-Change-Number: 7800003
      Gerrit-PatchSet: 5
      Gerrit-Owner: Christian Biesinger <cbies...@chromium.org>
      Gerrit-Reviewer: Christian Biesinger <cbies...@chromium.org>
      Gerrit-Reviewer: Nicolás Peña <n...@chromium.org>
      Gerrit-CC: Peter Beverloo <pe...@chromium.org>
      Gerrit-Comment-Date: Wed, 29 Apr 2026 16:58:34 +0000
      Gerrit-HasComments: Yes
      Gerrit-Has-Labels: No
      Comment-In-Reply-To: Nicolás Peña <n...@chromium.org>
      satisfied_requirement
      unsatisfied_requirement
      open
      diffy
      Reply all
      Reply to author
      Forward
      0 new messages