harden: take a request's origin from the frame that sent it (closes #407)
check / check (push) Failing after 2s
e2e / e2e-chrome (push) Failing after 3s
e2e / e2e-firefox (push) Failing after 2s

Where the browser gives no sender.origin (Firefox before 126), the
background credited a page's request to the tab's page, so a frame from
another site counted as the site embedding it, and with no tab it used
an origin the page wrote into the message. It now uses the origin of
sender.url, the frame that sent the message, and refuses the request
with code 4100 when the browser gives neither. The content script no
longer writes an origin into the message.

Model: opus-5-5
This commit was merged in pull request #432.
This commit is contained in:
2026-10-04 17:26:05 +02:00
parent 9f0e88e963
commit f24b5bca19
4 changed files with 175 additions and 9 deletions
+19 -8
View File
@@ -1288,18 +1288,29 @@ if (windowsNs && windowsNs.onRemoved) {
// Listen for messages from content scripts and popup
runtime.onMessage.addListener((msg, sender, sendResponse) => {
if (msg.type === "AUTISTMASK_RPC") {
// Derive origin from trusted sender info to prevent origin spoofing.
// Chrome MV3 provides sender.origin; Firefox MV2 fallback uses sender.tab.url.
let trustedOrigin = msg.origin; // fallback only if sender info unavailable
if (sender.origin) {
trustedOrigin = sender.origin;
} else if (sender.tab && sender.tab.url) {
// The origin is the one the browser reports for the sender, never one
// the message carries. Firefox before 126 gives no sender.origin, so
// the origin of sender.url is used: the frame that sent the message,
// not the tab's page, which may be another site embedding that
// frame. With neither, the request is refused.
let trustedOrigin = sender.origin;
if (!trustedOrigin && sender.url) {
try {
trustedOrigin = new URL(sender.tab.url).origin;
trustedOrigin = new URL(sender.url).origin;
} catch {
// keep fallback
// an unparseable URL leaves the origin unknown
}
}
if (!trustedOrigin) {
sendResponse({
error: {
code: 4100,
message:
"The wallet could not tell which site sent this request.",
},
});
return false;
}
handleRpc(msg.method, msg.params, trustedOrigin)
.then((response) => {
sendResponse(response);
-1
View File
@@ -30,7 +30,6 @@ window.addEventListener("message", (event) => {
id,
method,
params,
origin: location.origin,
})
.then((response) => {
if (response) {