Conversation
isKnownSender treated any URL as known in a packaged build:
ELECTRON_RENDERER_URL is unset there, so process.env.ELECTRON_RENDERER_URL
?? '' yielded the empty string and url.startsWith('') is always true. The
sender check then admitted any frame, not just the dev renderer.
Require a configured dev URL and match it exactly (or as a path prefix),
so the check admits the dev server origin and nothing else. A trailing
slash on the configured URL is stripped first, otherwise the '' + '/'
prefix doubles up and rejects the dev server's own query-string loads.
Add coverage for the unset, exact-match, trailing-slash, and unrelated-URL
cases.
Signed-off-by: woodsonl <65194841+woodsonl@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
isKnownSendertreated any URL as known in a packaged build.ELECTRON_RENDERER_URLis unset there, soprocess.env.ELECTRON_RENDERER_URL ?? ''produced the empty string, and
url.startsWith('')is always true. The sendercheck admitted any frame, not just the dev renderer.
This requires a configured dev URL and matches it exactly (or as a path
prefix), so the check admits the dev server origin and nothing else.
Release intent
Changelog title
n/a
Changelog body
n/a
Bumps
Scope
Included: the
isKnownSenderURL check and its test. Desktop-only; no servicebinary changes.
Excluded: nothing else in the IPC layer.
Validation
npm run typecheckindesktop/npx vitest run tests/modular/safe-handle-sender.test.tscovers the unsetdev URL, an exact match, and an unrelated URL.
Risk
Low. An unrelated URL is now correctly rejected; the dev server URL still
passes.
Checklist
git commit -s), certifying the Developer Certificate of Origin.services/versions.jsonis written by automation — do not edit it by hand.