security: announce a fresh EIP-6963 provider UUID per page load (closes #398)
The provider UUID was generated once, kept in extension storage and announced to every page on every load, so any site could read it as a stable identifier for the install across sites and browser restarts. inpage.js now generates one UUID per page load, shared by every announcement in that load, and stores nothing. The eip6963Uuid storage key and the AUTISTMASK_PROVIDER_UUID content-script message are removed. The key was never part of the versioned autistmask profile, so the state schema is untouched. Two inpage.js message listeners lose the leftover name onUuid. The test posts each load the same stored UUID the way the old content script did, and asserts that no load announces it and that two loads announce different UUIDs. Model: opus-5-5
This commit was merged in pull request #412.
This commit is contained in:
+9
-13
@@ -45,7 +45,7 @@
|
||||
}
|
||||
|
||||
// Listen for responses from the content script
|
||||
window.addEventListener("message", function onUuid(event) {
|
||||
window.addEventListener("message", (event) => {
|
||||
if (event.source !== window) return;
|
||||
if (event.data?.type !== "AUTISTMASK_RESPONSE") return;
|
||||
const { id, result, error } = event.data;
|
||||
@@ -60,7 +60,7 @@
|
||||
});
|
||||
|
||||
// Listen for events pushed from the extension
|
||||
window.addEventListener("message", function onUuid(event) {
|
||||
window.addEventListener("message", (event) => {
|
||||
if (event.source !== window) return;
|
||||
if (event.data?.type !== "AUTISTMASK_EVENT") return;
|
||||
const { eventName, data } = event.data;
|
||||
@@ -204,7 +204,13 @@
|
||||
"</svg>",
|
||||
);
|
||||
|
||||
let providerUuid = crypto.randomUUID(); // fallback until real UUID arrives
|
||||
// EIP-6963 asks for one UUIDv4 per provider for the life of the page: one
|
||||
// per page load, shared by every announcement in that load. It is
|
||||
// generated here and never stored: announcing one persisted value to every
|
||||
// site, on every load and across restarts, turned it into a stable
|
||||
// cross-site, cross-session tracking identifier any page could read
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/398).
|
||||
const providerUuid = crypto.randomUUID();
|
||||
|
||||
function buildProviderInfo() {
|
||||
return {
|
||||
@@ -226,16 +232,6 @@
|
||||
);
|
||||
}
|
||||
|
||||
// Listen for the persisted UUID from the content script
|
||||
function onProviderUuid(event) {
|
||||
if (event.source !== window) return;
|
||||
if (event.data?.type !== "AUTISTMASK_PROVIDER_UUID") return;
|
||||
window.removeEventListener("message", onProviderUuid);
|
||||
providerUuid = event.data.uuid;
|
||||
announceProvider();
|
||||
}
|
||||
window.addEventListener("message", onProviderUuid);
|
||||
|
||||
window.addEventListener("eip6963:requestProvider", announceProvider);
|
||||
announceProvider();
|
||||
|
||||
|
||||
Reference in New Issue
Block a user