cordova-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Montyleena (JIRA)" <>
Subject [jira] [Commented] (CB-3576) Add support for interstitial user confirmation of self-signed SSL certs to CordovaWebView and InAppBrowser
Date Fri, 10 Jan 2014 04:15:55 GMT


Montyleena commented on CB-3576:

Marcel, thanks for the detailed explanation :) The user confirmation is the ideal solution
to this. 
Joe: You can't reject this outright without thinking about all types of applications. The
solution Marcel shared is the need of the hour specially for Enterprise applications. You
can either ignore user feedback or choose to do some additional work and make it happen. It's
always a good thing to give the control to the user, and by blocking the URLs without asking
the user, PhoneGap is not doing that.

> Add support for interstitial user confirmation of self-signed SSL certs to CordovaWebView
and InAppBrowser
> ----------------------------------------------------------------------------------------------------------
>                 Key: CB-3576
>                 URL:
>             Project: Apache Cordova
>          Issue Type: Improvement
>          Components: Android, iOS, Plugin InAppBrowser
>    Affects Versions: 2.7.0, 2.8.0
>         Environment: Android and iOS
>            Reporter: Montyleena
>            Priority: Minor
>              Labels: android, https, inappbrowser,, ios, ssl
>         Attachments:
> Local https links are blocked by default in InAppBrowser (links using a local SSL certificate
which can't be verified by a 3rd party). Ideally, user should be given an option to proceed
or cancel the request like the default desktop/mobile browsers do. 
> Right now, we have to overwrite the following API in Android to access such URLs but
onReceivedSslError() function gets called only for the main PhoneGap window browser and not
for InAppBrowser.
> Create a new class:
> public class CustomWebViewClient extends CordovaWebViewClient {
> 	public static final String LOG_TAG = "Plugin";
> 	public CustomWebViewClient(DroidGap ctx) {
>         super(ctx);
>         Log.d(LOG_TAG, "Constructor!");
>     }
>     @Override
>     public void onReceivedSslError(WebView view, SslErrorHandler handler, SslError error)
>     	handler.proceed();
>     }
> }
> In the main class, we use our custom class as a web view client
>  CordovaWebViewClient webViewClient = new CustomWebViewClient(this);
>         webViewClient.setWebView(this.appView);
>         this.appView.setWebViewClient(webViewClient);
> And similar type of code needs to be written for iOS.
> InAppBrowser should pick up the SSL settings from the main web view and once we overwrite
the onReceivedSslError() function, then it should allow such URLs in the InAppBrowser too.

This message was sent by Atlassian JIRA

View raw message