WebAPI/Security/Contacts: Difference between revisions

Jump to navigation Jump to search
m
no edit summary
(Created page with "== Contacts API== Reference:https://wiki.mozilla.org/WebAPI/ContactsAPI Brief purpose of API: Access to users contacts. General Use Cases:N/A Inherent threats: *Read/exfiltrate...")
 
mNo edit summary
Line 13: Line 13:


=== Regular web content (unauthenticated) ===
=== Regular web content (unauthenticated) ===
Use cases for unauthenticated code: Mediated access limited contact
Use cases for unauthenticated code: Mediated access to specific (user selected) contact
information<br>
information
 
Authorization model for uninstalled web content: OS mediated (web
Authorization model for uninstalled web content: OS mediated (web
activities, or trusted UI)<br>
activities, or trusted UI)<br>
Authorization model for installed web content: OS mediated (web
Authorization model for installed web content: OS mediated (web
activities, or trusted UI)<br>
activities, or trusted UI)


Potential mitigations:
Potential mitigations:
Line 25: Line 26:


=== Trusted (authenticated by publisher) ===
=== Trusted (authenticated by publisher) ===
Use cases for authenticated code: Create,read or edit contact information<br>
Use cases for authenticated code: Create, read or edit contact information
Authorization model: Explicit<br>
 
Authorization model: Explicit
 
Potential mitigations:
Potential mitigations:
* Let user configure what data is accessible (globally?)
* Let user configure what data is accessible (globally?)
Line 34: Line 37:


=== Certified (vouched for by trusted 3rd party) ===
=== Certified (vouched for by trusted 3rd party) ===
Use cases for certified code: Create,read or edit contact information<br>
Use cases for certified code: Create, read or edit contact information
 
Authorization model: Implicit
Authorization model: Implicit
Potential mitigations: None
Potential mitigations: None
Confirmed users
717

edits

Navigation menu