harden: escape every interpolation into popup innerHTML, and add default-src to both manifests (closes #307)
A hostile ERC-20's symbol() reached an innerHTML string unescaped, and neither manifest declared default-src, so an attacker deploying a token with 1,000+ holders and airdropping one unit could render a full-viewport cross-origin iframe over the wallet's own UI, on screens where the user types their password. escapeHtml is now a pure string replace over & < > " ' — the old version round-tripped through textContent, which escapes neither quote, while already being used inside data-copy="...". All 19 files in src/popup/views/ were audited: beyond the reported symbol site, the explorer-supplied directionLabel in all three transaction lists, wallet.name, addr.ensName, the blockie data: URIs and two ad-hoc quote-only escapes were also unescaped. Explorer URLs now go through one helper that percent-encodes the path segment. Both manifests add default-src 'self', frame-src 'none', form-action 'none' and base-uri 'none'. Three loosenings are pinned in tests/manifest.test.js and justified in README.md: style-src 'unsafe-inline' (39 static style attributes; Firefox implements neither style-src-attr nor 'unsafe-hashes'), img-src data: (blockies), connect-src https: http: (user-configurable RPC). Note frame-src 'none' blocks a frame loading, not the element existing, so the zero-iframe assertion is a claim about the escaping alone; the test asserts the element count and the literal rendered text separately, taking the count before any click an overlay could intercept. Verified: make check 39 suites / 811 tests, test-e2e 55/55 including the WebAssembly-under-CSP assertion, test-e2e-firefox 8/8, zero CSP violations asserted rather than merely unobserved. Reverting only balanceLine's interpolation reproduces the attack as 2 iframes on the address screen.
This commit was merged in pull request #327.
This commit is contained in:
@@ -268,11 +268,15 @@ function ethCallResult(req, opts) {
|
||||
return ZERO_WORD;
|
||||
}
|
||||
|
||||
function tokenObject() {
|
||||
// opts.tokenSymbolOverride is the hostile contract: set it and the explorer
|
||||
// reports that string as the token's symbol, exactly as it would for a token
|
||||
// whose symbol() returns markup. Read at request time, like every other
|
||||
// fixture switch, so a test can flip it and reopen the popup.
|
||||
function tokenObject(opts) {
|
||||
return {
|
||||
address_hash: STUB_TOKEN.address,
|
||||
address: STUB_TOKEN.address,
|
||||
symbol: STUB_TOKEN.symbol,
|
||||
symbol: (opts && opts.tokenSymbolOverride) || STUB_TOKEN.symbol,
|
||||
name: STUB_TOKEN.name,
|
||||
decimals: STUB_TOKEN.decimals,
|
||||
holders_count: STUB_TOKEN.holders,
|
||||
@@ -281,7 +285,7 @@ function tokenObject() {
|
||||
}
|
||||
|
||||
// One received ERC-20 transfer of 1.5 E2E to the address under test.
|
||||
function tokenTransferItems(address) {
|
||||
function tokenTransferItems(address, opts) {
|
||||
return [
|
||||
{
|
||||
transaction_hash: STUB_TX_HASH,
|
||||
@@ -290,7 +294,7 @@ function tokenTransferItems(address) {
|
||||
from: { hash: STUB_COUNTERPARTY },
|
||||
to: { hash: address },
|
||||
total: { decimals: STUB_TOKEN.decimals, value: "1500000" },
|
||||
token: tokenObject(),
|
||||
token: tokenObject(opts),
|
||||
},
|
||||
];
|
||||
}
|
||||
@@ -317,11 +321,11 @@ function nativeTransactionItems(address) {
|
||||
// A holding of 1.5 E2E, in the shape src/shared/balances.js parses. Serving
|
||||
// this is what puts an ERC-20 in the send screen's token dropdown, which is
|
||||
// the only way the confirmation screen's ERC-20 path can be reached.
|
||||
function tokenBalanceItems() {
|
||||
function tokenBalanceItems(opts) {
|
||||
return [
|
||||
{
|
||||
value: "1500000",
|
||||
token: tokenObject(),
|
||||
token: tokenObject(opts),
|
||||
},
|
||||
];
|
||||
}
|
||||
@@ -596,6 +600,9 @@ function traceEnabled(raw) {
|
||||
* @param {string} [opts.tokenDecimalsOverride] what decimals() answers for
|
||||
* the stub token, in place of the value Blockscout reports for it. This is
|
||||
* the token that lies about its scale; read at request time.
|
||||
* @param {string} [opts.tokenSymbolOverride] what the explorer reports as
|
||||
* the stub token's symbol, in place of "E2E". This is the token whose
|
||||
* symbol is markup; read at request time.
|
||||
* @param {boolean} [opts.seedReceipt] answer eth_getTransactionReceipt with a
|
||||
* confirmed receipt instead of null, so a wait screen resolves.
|
||||
* @returns {Promise<{waitForServiceWorkerTraffic: (ms: number) =>
|
||||
@@ -674,14 +681,14 @@ async function installNetworkStubs(ctx, opts) {
|
||||
return jsonResponse(route, {
|
||||
items:
|
||||
opts.seedTokenTransfer && addr
|
||||
? tokenTransferItems(addr)
|
||||
? tokenTransferItems(addr, opts)
|
||||
: [],
|
||||
});
|
||||
}
|
||||
if (/\/addresses\/0x[0-9a-fA-F]{40}\/token-balances$/.test(p)) {
|
||||
return jsonResponse(
|
||||
route,
|
||||
opts.seedTokenBalance ? tokenBalanceItems() : [],
|
||||
opts.seedTokenBalance ? tokenBalanceItems(opts) : [],
|
||||
);
|
||||
}
|
||||
for (const hash of [STUB_TX_HASH, STUB_NATIVE_TX_HASH]) {
|
||||
|
||||
Reference in New Issue
Block a user