View Issue Details

IDProjectCategoryView StatusLast Update
0004745Talerwallet (WebExtensions)public2017-06-06 14:18
ReporterFlorian DoldAssigned ToFlorian Dold 
PrioritynormalSeverityminorReproducibilityhave not tried
Status closedResolutionfixed 
Product VersionSVN HEAD 
Target Version0.3Fixed in Version0.3 
Summary0004745: audit and fix cross origin merchant interaction issues in the wallet
DescriptionRight now we don't check the origin for all operations where we should.
TagsNo tags attached.

Activities

Florian Dold

2017-04-13 15:54

manager   ~0012036

This is obsolete now, since we only query contracts via the full URL of the page that we're on. There is no other way to query contracts, and thus no cross origin issues can arise, where merchant foo.taler.net can query a contract from merchant bar.taler.net.

Issue History

Date Modified Username Field Change
2016-10-19 21:36 Florian Dold New Issue
2016-10-19 21:36 Florian Dold Status new => assigned
2016-10-19 21:36 Florian Dold Assigned To => Florian Dold
2016-11-15 15:55 Christian Grothoff Product Version => SVN HEAD
2016-11-15 15:55 Christian Grothoff Target Version => 0.3
2017-04-13 15:54 Florian Dold Note Added: 0012036
2017-04-13 15:54 Florian Dold Status assigned => resolved
2017-04-13 15:54 Florian Dold Resolution open => fixed
2017-04-15 20:02 Christian Grothoff Fixed in Version => 0.3
2017-06-06 14:18 Christian Grothoff Status resolved => closed