harden: take a request's origin from the frame that sent it (closes #407)
Where the browser gives no sender.origin (Firefox before 126), the background credited a page's request to the tab's page, so a frame from another site counted as the site embedding it, and with no tab it used an origin the page wrote into the message. It now uses the origin of sender.url, the frame that sent the message, and refuses the request with code 4100 when the browser gives neither. The content script no longer writes an origin into the message. Model: opus-5-5
This commit was merged in pull request #432.
This commit is contained in:
@@ -45,6 +45,15 @@ but the review is broader than any of them.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: A page's request is credited only to the site the browser says
|
||||
sent it ([#407](https://git.eeqj.de/sneak/AutistMask/issues/407)). Where the
|
||||
browser does not give the sender's origin (Firefox before 126), the background
|
||||
used the tab's page, so a frame from another site would have been treated as
|
||||
the site embedding it, and with no tab it used an origin the page wrote into
|
||||
the message. It now uses the URL of the frame that sent the message, and
|
||||
refuses the request with code 4100 when the browser gives neither. The content
|
||||
script no longer writes an origin into the message.
|
||||
|
||||
- 2026-10-04: `make test` takes 8-13s on the shared build host, down from
|
||||
17-25s, measured in alternating runs before and after the change
|
||||
([#428](https://git.eeqj.de/sneak/AutistMask/issues/428)). Each popup boot in
|
||||
|
||||
Reference in New Issue
Block a user