Files
AutistMask/src/content/index.js
T
clawbot add11e57de
check / check (push) Successful in 1m4s
e2e / e2e-chrome (push) Successful in 1m47s
e2e / e2e-firefox (push) Successful in 33s
security: announce a fresh EIP-6963 provider UUID per page load (closes #398)
The provider UUID was generated once, kept in extension storage and
announced to every page on every load, so any site could read it as a
stable identifier for the install across sites and browser restarts.

inpage.js now generates one UUID per page load, shared by every
announcement in that load, and stores nothing. The eip6963Uuid storage
key and the AUTISTMASK_PROVIDER_UUID content-script message are removed.
The key was never part of the versioned autistmask profile, so the state
schema is untouched. Two inpage.js message listeners lose the leftover
name onUuid.

The test posts each load the same stored UUID the way the old content
script did, and asserts that no load announces it and that two loads
announce different UUIDs.

Model: opus-5-5
2026-10-03 16:26:39 +02:00

64 lines
2.0 KiB
JavaScript

// AutistMask content script — bridges between inpage (window.ethereum)
// and the background service worker via extension messaging.
const {
hasBrowserNamespace,
runtimeApi,
sendMessage,
} = require("../shared/browserApi");
// In Chrome (MV3), inpage.js runs as a MAIN-world content script declared
// in the manifest, so no injection is needed here. In Firefox (MV2), the
// "world" key is not supported, so we inject via a <script> tag.
if (hasBrowserNamespace()) {
const script = document.createElement("script");
script.src = runtimeApi().getURL("src/content/inpage.js");
script.onload = function () {
this.remove();
};
(document.head || document.documentElement).appendChild(script);
}
// Relay requests from the page to the background script
window.addEventListener("message", (event) => {
if (event.source !== window) return;
if (event.data?.type !== "AUTISTMASK_REQUEST") return;
const { id, method, params } = event.data;
sendMessage({
type: "AUTISTMASK_RPC",
id,
method,
params,
origin: location.origin,
})
.then((response) => {
if (response) {
window.postMessage(
{ type: "AUTISTMASK_RESPONSE", id, ...response },
"*",
);
}
})
.catch(() => {
// No receiver: the background context is gone. The page's promise
// stays pending, which is what it did before this was a promise
// at all; turning it into a rejection here is a change to what
// dApps see and belongs to its own issue.
});
});
// Listen for events pushed from the background (e.g. accountsChanged)
runtimeApi().onMessage.addListener((msg) => {
if (msg.type === "AUTISTMASK_EVENT") {
window.postMessage(
{
type: "AUTISTMASK_EVENT",
eventName: msg.eventName,
data: msg.data,
},
"*",
);
}
});