mirror of
https://github.com/mozilla/gecko-dev.git
synced 2024-11-25 22:01:30 +00:00
bce88244c0
Credential Management defines a parameter `sameOriginWithAncestors` which is set true if the responsible document is not either in a top-level browsing context, or is in a nested context whose heirarchy is all loaded from the same origin as the top-level context [1][2]. The individual credential types of CredMan can use this flag to make decisions on whether to error or not. Our Credential Management implementation right now is a shim to Web Authentication, which says that if `sameOriginWithAncestors` is false, return `"NotAllowedError"`. This ensures that https://webauthn.bin.coffee/iframe.html works, but the cross-origin https://u2f.bin.coffee/iframe-webauthn.html does not. [1] https://w3c.github.io/webappsec-credential-management/#algorithm-request [2] https://w3c.github.io/webappsec-credential-management/#algorithm-create [3] https://w3c.github.io/webauthn/#createCredential [4] https://w3c.github.io/webauthn/#getAssertion MozReview-Commit-ID: KIyakgl0kGv --HG-- extra : rebase_source : dace4f4d73823913bff759fce8255da8e18ad5e3
57 lines
1.5 KiB
C++
57 lines
1.5 KiB
C++
/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */
|
|
/* vim: set ts=8 sts=2 et sw=2 tw=80: */
|
|
/* This Source Code Form is subject to the terms of the Mozilla Public
|
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
|
|
|
|
#ifndef mozilla_dom_CredentialsContainer_h
|
|
#define mozilla_dom_CredentialsContainer_h
|
|
|
|
#include "mozilla/dom/CredentialManagementBinding.h"
|
|
|
|
namespace mozilla {
|
|
namespace dom {
|
|
|
|
class WebAuthnManager;
|
|
|
|
class CredentialsContainer final : public nsISupports
|
|
, public nsWrapperCache
|
|
{
|
|
public:
|
|
NS_DECL_CYCLE_COLLECTING_ISUPPORTS
|
|
NS_DECL_CYCLE_COLLECTION_SCRIPT_HOLDER_CLASS(CredentialsContainer)
|
|
|
|
explicit CredentialsContainer(nsPIDOMWindowInner* aParent);
|
|
|
|
nsPIDOMWindowInner*
|
|
GetParentObject() const
|
|
{
|
|
return mParent;
|
|
}
|
|
|
|
virtual JSObject*
|
|
WrapObject(JSContext* aCx, JS::Handle<JSObject*> aGivenProto) override;
|
|
|
|
already_AddRefed<Promise>
|
|
Get(const CredentialRequestOptions& aOptions, ErrorResult& aRv);
|
|
|
|
already_AddRefed<Promise>
|
|
Create(const CredentialCreationOptions& aOptions, ErrorResult& aRv);
|
|
|
|
already_AddRefed<Promise>
|
|
Store(const Credential& aCredential, ErrorResult& aRv);
|
|
|
|
private:
|
|
~CredentialsContainer();
|
|
|
|
void EnsureWebAuthnManager();
|
|
|
|
nsCOMPtr<nsPIDOMWindowInner> mParent;
|
|
RefPtr<WebAuthnManager> mManager;
|
|
};
|
|
|
|
} // namespace dom
|
|
} // namespace mozilla
|
|
|
|
#endif // mozilla_dom_CredentialsContainer_h
|