The AUTISTMASK_RPC handler in src/background/index.js takes a request's origin from sender.origin, then from the origin of sender.url, the frame that sent the message. The sender.tab.url and msg.origin fallbacks are gone. A request with neither is answered with code 4100 and "The wallet could not tell which site sent this request." The content script no longer puts origin in the message, since nothing reads it now.
Worth knowing:
Neither manifest sets all_frames, so the content script runs only in the top frame today and the frame case cannot happen on a shipped build. As the issue says, this is defence in depth.
On current Chrome and Firefox sender.origin is always present, so nothing changes there.
A sender.url that does not parse counts as no URL, and the request is refused.
Tests (tests/rpcOrigin.test.js): a stranger's frame on a connected site gets no address, a connected site's frame on a stranger's page gets it, and a sender with neither origin nor url is refused even when the tab and the message name a connected site. All three fail without the fix.
Judgement call: removing origin from the content script's message is outside the handler, but leaving an unread field there would suggest the page's word still counts.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/AutistMask/issues/407.
The `AUTISTMASK_RPC` handler in `src/background/index.js` takes a request's origin from `sender.origin`, then from the origin of `sender.url`, the frame that sent the message. The `sender.tab.url` and `msg.origin` fallbacks are gone. A request with neither is answered with code 4100 and "The wallet could not tell which site sent this request." The content script no longer puts `origin` in the message, since nothing reads it now.
Worth knowing:
- Neither manifest sets `all_frames`, so the content script runs only in the top frame today and the frame case cannot happen on a shipped build. As the issue says, this is defence in depth.
- On current Chrome and Firefox `sender.origin` is always present, so nothing changes there.
- A `sender.url` that does not parse counts as no URL, and the request is refused.
Tests (`tests/rpcOrigin.test.js`): a stranger's frame on a connected site gets no address, a connected site's frame on a stranger's page gets it, and a sender with neither `origin` nor `url` is refused even when the tab and the message name a connected site. All three fail without the fix.
Judgement call: removing `origin` from the content script's message is outside the handler, but leaving an unread field there would suggest the page's word still counts.
Model: opus-5-5
Where the browser gives no sender.origin (Firefox before 126), the
background credited a page's request to the tab's page, so a frame from
another site counted as the site embedding it, and with no tab it used
an origin the page wrote into the message. It now uses the origin of
sender.url, the frame that sent the message, and refuses the request
with code 4100 when the browser gives neither. The content script no
longer writes an origin into the message.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #407.
The
AUTISTMASK_RPChandler insrc/background/index.jstakes a request's origin fromsender.origin, then from the origin ofsender.url, the frame that sent the message. Thesender.tab.urlandmsg.originfallbacks are gone. A request with neither is answered with code 4100 and "The wallet could not tell which site sent this request." The content script no longer putsoriginin the message, since nothing reads it now.Worth knowing:
all_frames, so the content script runs only in the top frame today and the frame case cannot happen on a shipped build. As the issue says, this is defence in depth.sender.originis always present, so nothing changes there.sender.urlthat does not parse counts as no URL, and the request is refused.Tests (
tests/rpcOrigin.test.js): a stranger's frame on a connected site gets no address, a connected site's frame on a stranger's page gets it, and a sender with neitheroriginnorurlis refused even when the tab and the message name a connected site. All three fail without the fix.Judgement call: removing
originfrom the content script's message is outside the handler, but leaving an unread field there would suggest the page's word still counts.Model: opus-5-5
PASS
Model: opus-5-5