Files
brave-core/browser/widevine
Claudio DeSouza 40c3d6b3dd [cr149] ContentSettingPermissionResolver dropped from request data
This changes the constructor calls, and this change corrects that. For
the only use of `PermissionDescriptor` in the constructor, a default
constructor is being used because there is no blink value for the
permission name for `RequestType::kBraveOpenAIChat`, so we set that
separately.

Chromium changes:
https://chromium.googlesource.com/chromium/src/+/35ad82c9803604df82915104d4d062cd851214f7

commit 35ad82c9803604df82915104d4d062cd851214f7
Author: Antonio Sartori <antoniosartori@chromium.org>
Date:   Thu Apr 23 10:37:35 2026 -0700

    [permissions] Refactor PermissionRequestData

    This CL refactors PermissionRequestData so that it becomes again a
    data-only struct (which can be e.g. cloned) by removing the
    PermissionResolver member. This allows simplifying
    GeolocationPermissionContextAndroid, where we don't need to recreate
    fake PermissionRequestData for the callbacks anymore.

    The refactoring unfortunately implies adapting all callsites, which
    however become more natural as they don't need to instantiate a
    PermissionResolver anymore.

    R=hempjudith@google.com

    Change-Id: Ib7883e9f7cac32ef4039ce3098275ad9018f47d3
    Bug: 443898320
    Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7780845
    Commit-Queue: Antonio Sartori <antoniosartori@chromium.org>
    Reviewed-by: Javier Fernandez <jfernandez@igalia.com>
    Reviewed-by: Judith Hemp <hempjudith@google.com>
    Reviewed-by: Marc Treib <treib@chromium.org>
    Cr-Commit-Position: refs/heads/main@{#1619624}
2026-05-22 16:25:11 -04:00
..

Widevine in Brave

Widevine is used to decrypt DRM-protected content, which is served from streaming services such as Netflix. Widevine is integrated in Chromium as a component.

Signature files (brave.exe.sig, chrome.dll.sig, ...)

Streaming services only offer high definition content to clients that are trusted. Widevine has mechanisms to ensure the integrity of the client. One of these mechanisms are .sig files. They prove to Widevine that the browser has not been tampered with. In order for Brave's users to see high-definition content, the browser must generate and ship with those .sig files.

Licensing

Brave's licensing agreement for Widevine forbids distribution of Widevine's binaries. This entails several workarounds, some of which are listed below.

Workarounds

Sequential component updates: SequentialUpdateChecker

Brave has its own components and thus uses its own component update server. This server also gets polled by the browser for Widevine. To comply with the licensing restriction described above, Brave's component update server responds with a redirect to Google's server in this case. This works as long as a single update check request only polls for Widevine, and not also for any other components. We have a special class, SequentialUpdateChecker, that makes sure that this is the case.