harden: take a request's origin from the frame that sent it (closes #407)
Where the browser gives no sender.origin (Firefox before 126), the background credited a page's request to the tab's page, so a frame from another site counted as the site embedding it, and with no tab it used an origin the page wrote into the message. It now uses the origin of sender.url, the frame that sent the message, and refuses the request with code 4100 when the browser gives neither. The content script no longer writes an origin into the message. Model: opus-5-5
This commit was merged in pull request #432.
This commit is contained in:
+19
-8
@@ -1288,18 +1288,29 @@ if (windowsNs && windowsNs.onRemoved) {
|
||||
// Listen for messages from content scripts and popup
|
||||
runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
||||
if (msg.type === "AUTISTMASK_RPC") {
|
||||
// Derive origin from trusted sender info to prevent origin spoofing.
|
||||
// Chrome MV3 provides sender.origin; Firefox MV2 fallback uses sender.tab.url.
|
||||
let trustedOrigin = msg.origin; // fallback only if sender info unavailable
|
||||
if (sender.origin) {
|
||||
trustedOrigin = sender.origin;
|
||||
} else if (sender.tab && sender.tab.url) {
|
||||
// The origin is the one the browser reports for the sender, never one
|
||||
// the message carries. Firefox before 126 gives no sender.origin, so
|
||||
// the origin of sender.url is used: the frame that sent the message,
|
||||
// not the tab's page, which may be another site embedding that
|
||||
// frame. With neither, the request is refused.
|
||||
let trustedOrigin = sender.origin;
|
||||
if (!trustedOrigin && sender.url) {
|
||||
try {
|
||||
trustedOrigin = new URL(sender.tab.url).origin;
|
||||
trustedOrigin = new URL(sender.url).origin;
|
||||
} catch {
|
||||
// keep fallback
|
||||
// an unparseable URL leaves the origin unknown
|
||||
}
|
||||
}
|
||||
if (!trustedOrigin) {
|
||||
sendResponse({
|
||||
error: {
|
||||
code: 4100,
|
||||
message:
|
||||
"The wallet could not tell which site sent this request.",
|
||||
},
|
||||
});
|
||||
return false;
|
||||
}
|
||||
handleRpc(msg.method, msg.params, trustedOrigin)
|
||||
.then((response) => {
|
||||
sendResponse(response);
|
||||
|
||||
@@ -30,7 +30,6 @@ window.addEventListener("message", (event) => {
|
||||
id,
|
||||
method,
|
||||
params,
|
||||
origin: location.origin,
|
||||
})
|
||||
.then((response) => {
|
||||
if (response) {
|
||||
|
||||
Reference in New Issue
Block a user