Where the browser gives no sender.origin (Firefox before 126), the background credited a page's request to the tab's page, so a frame from another site counted as the site embedding it, and with no tab it used an origin the page wrote into the message. It now uses the origin of sender.url, the frame that sent the message, and refuses the request with code 4100 when the browser gives neither. The content script no longer writes an origin into the message. Model: opus-5-5
63 lines
2.0 KiB
JavaScript
63 lines
2.0 KiB
JavaScript
// AutistMask content script — bridges between inpage (window.ethereum)
|
|
// and the background service worker via extension messaging.
|
|
|
|
const {
|
|
hasBrowserNamespace,
|
|
runtimeApi,
|
|
sendMessage,
|
|
} = require("../shared/browserApi");
|
|
|
|
// In Chrome (MV3), inpage.js runs as a MAIN-world content script declared
|
|
// in the manifest, so no injection is needed here. In Firefox (MV2), the
|
|
// "world" key is not supported, so we inject via a <script> tag.
|
|
if (hasBrowserNamespace()) {
|
|
const script = document.createElement("script");
|
|
script.src = runtimeApi().getURL("src/content/inpage.js");
|
|
script.onload = function () {
|
|
this.remove();
|
|
};
|
|
(document.head || document.documentElement).appendChild(script);
|
|
}
|
|
|
|
// Relay requests from the page to the background script
|
|
window.addEventListener("message", (event) => {
|
|
if (event.source !== window) return;
|
|
if (event.data?.type !== "AUTISTMASK_REQUEST") return;
|
|
const { id, method, params } = event.data;
|
|
|
|
sendMessage({
|
|
type: "AUTISTMASK_RPC",
|
|
id,
|
|
method,
|
|
params,
|
|
})
|
|
.then((response) => {
|
|
if (response) {
|
|
window.postMessage(
|
|
{ type: "AUTISTMASK_RESPONSE", id, ...response },
|
|
"*",
|
|
);
|
|
}
|
|
})
|
|
.catch(() => {
|
|
// No receiver: the background context is gone. The page's promise
|
|
// stays pending, which is what it did before this was a promise
|
|
// at all; turning it into a rejection here is a change to what
|
|
// dApps see and belongs to its own issue.
|
|
});
|
|
});
|
|
|
|
// Listen for events pushed from the background (e.g. accountsChanged)
|
|
runtimeApi().onMessage.addListener((msg) => {
|
|
if (msg.type === "AUTISTMASK_EVENT") {
|
|
window.postMessage(
|
|
{
|
|
type: "AUTISTMASK_EVENT",
|
|
eventName: msg.eventName,
|
|
data: msg.data,
|
|
},
|
|
"*",
|
|
);
|
|
}
|
|
});
|