Files
AutistMask/src/content/index.js
T
clawbot f24b5bca19
check / check (push) Failing after 2s
e2e / e2e-chrome (push) Failing after 3s
e2e / e2e-firefox (push) Failing after 2s
harden: take a request's origin from the frame that sent it (closes #407)
Where the browser gives no sender.origin (Firefox before 126), the
background credited a page's request to the tab's page, so a frame from
another site counted as the site embedding it, and with no tab it used
an origin the page wrote into the message. It now uses the origin of
sender.url, the frame that sent the message, and refuses the request
with code 4100 when the browser gives neither. The content script no
longer writes an origin into the message.

Model: opus-5-5
2026-10-04 17:26:05 +02:00

63 lines
2.0 KiB
JavaScript

// AutistMask content script — bridges between inpage (window.ethereum)
// and the background service worker via extension messaging.
const {
hasBrowserNamespace,
runtimeApi,
sendMessage,
} = require("../shared/browserApi");
// In Chrome (MV3), inpage.js runs as a MAIN-world content script declared
// in the manifest, so no injection is needed here. In Firefox (MV2), the
// "world" key is not supported, so we inject via a <script> tag.
if (hasBrowserNamespace()) {
const script = document.createElement("script");
script.src = runtimeApi().getURL("src/content/inpage.js");
script.onload = function () {
this.remove();
};
(document.head || document.documentElement).appendChild(script);
}
// Relay requests from the page to the background script
window.addEventListener("message", (event) => {
if (event.source !== window) return;
if (event.data?.type !== "AUTISTMASK_REQUEST") return;
const { id, method, params } = event.data;
sendMessage({
type: "AUTISTMASK_RPC",
id,
method,
params,
})
.then((response) => {
if (response) {
window.postMessage(
{ type: "AUTISTMASK_RESPONSE", id, ...response },
"*",
);
}
})
.catch(() => {
// No receiver: the background context is gone. The page's promise
// stays pending, which is what it did before this was a promise
// at all; turning it into a rejection here is a change to what
// dApps see and belongs to its own issue.
});
});
// Listen for events pushed from the background (e.g. accountsChanged)
runtimeApi().onMessage.addListener((msg) => {
if (msg.type === "AUTISTMASK_EVENT") {
window.postMessage(
{
type: "AUTISTMASK_EVENT",
eventName: msg.eventName,
data: msg.data,
},
"*",
);
}
});