security: announce a fresh EIP-6963 provider UUID per page load (closes #398)
The provider UUID was generated once, kept in extension storage and announced to every page on every load, so any site could read it as a stable identifier for the install across sites and browser restarts. inpage.js now generates one UUID per page load, shared by every announcement in that load, and stores nothing. The eip6963Uuid storage key and the AUTISTMASK_PROVIDER_UUID content-script message are removed. The key was never part of the versioned autistmask profile, so the state schema is untouched. Two inpage.js message listeners lose the leftover name onUuid. The test posts each load the same stored UUID the way the old content script did, and asserts that no load announces it and that two loads announce different UUIDs. Model: opus-5-5
This commit was merged in pull request #412.
This commit is contained in:
@@ -372,10 +372,10 @@ step("the loopback dApp page gets the real inpage provider", async (env) => {
|
||||
STEP_TIMEOUT_MS,
|
||||
);
|
||||
|
||||
// EIP-6963, asked of the provider itself. The announcement carries the
|
||||
// uuid src/content/index.js reads out of extension storage — call site 1
|
||||
// in the issue — and it has to name this extension and hand back the very
|
||||
// object on window.ethereum.
|
||||
// EIP-6963, asked of the provider itself. The announcement carries a
|
||||
// UUIDv4 inpage.js generates fresh for this page load (nothing persists
|
||||
// it — see issue #398) and has to name this extension and hand back the
|
||||
// very object on window.ethereum.
|
||||
const announced = await d.executeAsync(
|
||||
`const done = arguments[arguments.length - 1];
|
||||
const onAnnounce = (e) => {
|
||||
@@ -402,7 +402,7 @@ step("the loopback dApp page gets the real inpage provider", async (env) => {
|
||||
);
|
||||
assert(
|
||||
typeof announced.uuid === "string" && announced.uuid.length === 36,
|
||||
"the announcement carries no stored provider uuid: " +
|
||||
"the announcement carries no provider uuid: " +
|
||||
JSON.stringify(announced.uuid),
|
||||
);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user