You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When the app redirects the user to an issuer or verifier, there is no visual indication that the user is viewing an external web site and not the main app (see attached video).
wwwallet_android-no_hint_webview_switch.mp4
Besides being potentially confusing, it could also lead to security issues - the issuer/verifier web site could be styled to look like the main wwWallet app and trick the user into giving away their passkey PIN or other sensitive information.
Proposed solution
Add a "banner" or something similar to a browser URL bar that indicates that what external content is being displayed.
Problem description
When the app redirects the user to an issuer or verifier, there is no visual indication that the user is viewing an external web site and not the main app (see attached video).
wwwallet_android-no_hint_webview_switch.mp4
Besides being potentially confusing, it could also lead to security issues - the issuer/verifier web site could be styled to look like the main wwWallet app and trick the user into giving away their passkey PIN or other sensitive information.
Proposed solution
Add a "banner" or something similar to a browser URL bar that indicates that what external content is being displayed.