harden: key remembered site permissions by full origin (closes #402)
allowedSites and deniedSites held the bare hostname, so a grant to https://dapp.example also authorised http://dapp.example and every port on that host, and the connection, transaction and signature prompts named only the hostname. Both lists now store and match the full origin (scheme://host[:port]), the key the connections approved without Remember already used. The prompts, the Settings site lists and AUTISTMASK_REMOVE_SITE use the origin too. Entries saved by hostname are not migrated (pre-1.0): they match no site. Model: opus-5-5
This commit was merged in pull request #431.
This commit is contained in:
@@ -1561,7 +1561,7 @@
|
||||
with extreme caution.
|
||||
</div>
|
||||
<p class="mb-2">
|
||||
<span id="approve-tx-hostname" class="font-bold"></span>
|
||||
<span id="approve-tx-origin" class="font-bold"></span>
|
||||
wants to send a transaction.
|
||||
</p>
|
||||
|
||||
@@ -1662,7 +1662,7 @@
|
||||
funds. Proceed with extreme caution.
|
||||
</div>
|
||||
<p class="mb-2">
|
||||
<span id="approve-sign-hostname" class="font-bold"></span>
|
||||
<span id="approve-sign-origin" class="font-bold"></span>
|
||||
wants you to sign a message.
|
||||
</p>
|
||||
|
||||
@@ -1740,7 +1740,7 @@
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<p class="mb-2">
|
||||
<span id="approve-hostname" class="font-bold"></span>
|
||||
<span id="approve-origin" class="font-bold"></span>
|
||||
wants to connect to your wallet.
|
||||
</p>
|
||||
<div class="text-xs text-muted mb-1">
|
||||
|
||||
@@ -306,7 +306,7 @@ function showTxApproval(details) {
|
||||
};
|
||||
}
|
||||
|
||||
$("approve-tx-hostname").textContent = details.hostname;
|
||||
$("approve-tx-origin").textContent = details.origin;
|
||||
$("approve-tx-from").innerHTML = approvalAddressHtml(details.approvedFrom);
|
||||
|
||||
// Show token symbol next to contract address if known
|
||||
@@ -645,7 +645,7 @@ function showSignApproval(details) {
|
||||
pendingSignParams = sp;
|
||||
pendingSignFrom = details.approvedFrom;
|
||||
|
||||
$("approve-sign-hostname").textContent = details.hostname;
|
||||
$("approve-sign-origin").textContent = details.origin;
|
||||
$("approve-sign-from").innerHTML = approvalAddressHtml(
|
||||
details.approvedFrom,
|
||||
);
|
||||
@@ -732,7 +732,7 @@ async function show(id) {
|
||||
"approve-site-phishing-warning",
|
||||
details.isPhishingDomain,
|
||||
);
|
||||
$("approve-hostname").textContent = details.hostname;
|
||||
$("approve-origin").textContent = details.origin;
|
||||
$("approve-address").innerHTML = approvalAddressHtml(state.activeAddress);
|
||||
attachCopyHandlers("view-approve-site");
|
||||
$("approve-remember").checked = state.rememberSiteChoice;
|
||||
|
||||
+17
-17
@@ -34,35 +34,35 @@ const { notify, sendMessage } = require("../../shared/browserApi");
|
||||
let versionClickCount = 0;
|
||||
let versionClickTimer = null;
|
||||
|
||||
// One row per hostname, however many addresses or origins it appears under,
|
||||
// each with an [x] that hands it to onRemove.
|
||||
function renderSiteList(containerId, hostnames, onRemove) {
|
||||
// One row per site origin, however many addresses it appears under, each with
|
||||
// an [x] that hands it to onRemove.
|
||||
function renderSiteList(containerId, origins, onRemove) {
|
||||
const container = $(containerId);
|
||||
const unique = [...new Set(hostnames)];
|
||||
const unique = [...new Set(origins)];
|
||||
if (unique.length === 0) {
|
||||
container.innerHTML = '<p class="text-xs text-muted">None</p>';
|
||||
return;
|
||||
}
|
||||
let html = "";
|
||||
unique.forEach((hostname) => {
|
||||
unique.forEach((origin) => {
|
||||
html += `<div class="flex justify-between items-center text-xs py-1 border-b border-border-light">`;
|
||||
// A hostname the URL parser produced cannot carry a delimiter, so
|
||||
// An origin the URL parser produced cannot carry a delimiter, so
|
||||
// this is escaped for the rule rather than for a known hole — the
|
||||
// rule being that nothing reaches innerHTML unescaped.
|
||||
html += `<span>${escapeHtml(hostname)}</span>`;
|
||||
html += `<button class="btn-remove-site border border-border px-1 hover:bg-fg hover:text-bg cursor-pointer" data-hostname="${escapeHtml(hostname)}">[x]</button>`;
|
||||
html += `<span>${escapeHtml(origin)}</span>`;
|
||||
html += `<button class="btn-remove-site border border-border px-1 hover:bg-fg hover:text-bg cursor-pointer" data-origin="${escapeHtml(origin)}">[x]</button>`;
|
||||
html += `</div>`;
|
||||
});
|
||||
container.innerHTML = html;
|
||||
container.querySelectorAll(".btn-remove-site").forEach((btn) => {
|
||||
btn.addEventListener("click", () => onRemove(btn.dataset.hostname));
|
||||
btn.addEventListener("click", () => onRemove(btn.dataset.origin));
|
||||
});
|
||||
}
|
||||
|
||||
// Drop a hostname from a remembered site list under every address.
|
||||
function forgetHostname(siteMap, hostname) {
|
||||
// Drop a site origin from a remembered site list under every address.
|
||||
function forgetOrigin(siteMap, origin) {
|
||||
for (const addr of Object.keys(siteMap)) {
|
||||
siteMap[addr] = siteMap[addr].filter((h) => h !== hostname);
|
||||
siteMap[addr] = siteMap[addr].filter((o) => o !== origin);
|
||||
if (siteMap[addr].length === 0) {
|
||||
delete siteMap[addr];
|
||||
}
|
||||
@@ -72,16 +72,16 @@ function forgetHostname(siteMap, hostname) {
|
||||
// Removing a site from Allowed Sites or Connected Sites disconnects it: it is
|
||||
// no longer allowed under any address, and the background ends its
|
||||
// connections approved without "Remember" and tells its open tabs.
|
||||
async function removeAllowedSite(hostname) {
|
||||
forgetHostname(state.allowedSites, hostname);
|
||||
async function removeAllowedSite(origin) {
|
||||
forgetOrigin(state.allowedSites, origin);
|
||||
await saveState();
|
||||
notify({ type: "AUTISTMASK_REMOVE_SITE", hostname });
|
||||
notify({ type: "AUTISTMASK_REMOVE_SITE", origin });
|
||||
await renderSiteLists();
|
||||
}
|
||||
|
||||
// Removing a denied site only forgets the refusal; it connects nothing.
|
||||
async function removeDeniedSite(hostname) {
|
||||
forgetHostname(state.deniedSites, hostname);
|
||||
async function removeDeniedSite(origin) {
|
||||
forgetOrigin(state.deniedSites, origin);
|
||||
await saveState();
|
||||
await renderSiteLists();
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user