Skip to content

Add UI process gesture verification step - #506

Open
marcoscaceres wants to merge 4 commits into
mainfrom
ui-process-gesture-verification
Open

Add UI process gesture verification step#506
marcoscaceres wants to merge 4 commits into
mainfrom
ui-process-gesture-verification

Conversation

@marcoscaceres

@marcoscaceres marcoscaceres commented Apr 29, 2026

Copy link
Copy Markdown
Collaborator

Related to #472 — addresses the gesture verification aspect

  • Adds a SHOULD-level requirement for user agents to independently verify that the credential request was initiated by a genuine user gesture, using a trusted process rather than solely relying on the content process
  • Defense in depth against compromised renderers presenting the digital credential chooser without actual user activation

The following tasks have been completed:

  • Modified Web platform tests - not testable

Implementation commitment:

  • WebKit (Bug 312458)
  • Chromium - mitigation already in place.
  • Gecko (link to issue)

Documentation and checks

  • Affects privacy
  • Affects security
  • Pinged MDN
  • Updated Explainer
  • Updated digitalcredentials.dev

Preview | Diff

Base automatically changed from present to main April 30, 2026 00:21
SHOULD-level requirement for user agents to independently verify
that the credential request was initiated by a genuine user gesture,
using a trusted process rather than solely relying on the content
process. Defense in depth against compromised renderers.
@marcoscaceres
marcoscaceres force-pushed the ui-process-gesture-verification branch from 63e035f to b4e45e8 Compare April 30, 2026 04:51
@marcoscaceres
marcoscaceres marked this pull request as ready for review July 7, 2026 07:02
@marcoscaceres
marcoscaceres requested a review from a team as a code owner July 7, 2026 07:02
@marcoscaceres
marcoscaceres requested a review from mohamedamir July 7, 2026 07:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants