harden: key remembered site permissions by full origin (closes #402)
check / check (push) Failing after 2s
e2e / e2e-chrome (push) Failing after 2s
e2e / e2e-firefox (push) Failing after 2s

allowedSites and deniedSites held the bare hostname, so a grant to
https://dapp.example also authorised http://dapp.example and every port
on that host, and the connection, transaction and signature prompts
named only the hostname. Both lists now store and match the full origin
(scheme://host[:port]), the key the connections approved without
Remember already used. The prompts, the Settings site lists and
AUTISTMASK_REMOVE_SITE use the origin too. Entries saved by hostname
are not migrated (pre-1.0): they match no site.

Model: opus-5-5
This commit is contained in:
2026-10-04 15:02:14 +00:00
parent 9f0e88e963
commit 30f57b9076
28 changed files with 469 additions and 229 deletions
+2 -2
View File
@@ -165,7 +165,7 @@ const CONTRACT = [
[ADDRESS],
{ [ADDRESS]: 42 },
{ [ADDRESS]: [42, null, {}] },
JSON.parse('{"__proto__":["evil.invalid"]}'),
JSON.parse('{"__proto__":["https://evil.invalid"]}'),
],
holds: siteMapHolds,
},
@@ -177,7 +177,7 @@ const CONTRACT = [
[ADDRESS],
{ [ADDRESS]: 42 },
{ [ADDRESS]: [42, null, {}] },
JSON.parse('{"__proto__":["evil.invalid"]}'),
JSON.parse('{"__proto__":["https://evil.invalid"]}'),
],
holds: siteMapHolds,
},