We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent ce31305 commit 669d77eCopy full SHA for 669d77e
1 file changed
src/background/index.mjs
@@ -717,7 +717,13 @@ Browser.runtime.onMessage.addListener(async (message, sender) => {
717
}
718
719
case 'GET_COOKIE': {
720
- console.log('[background] Processing GET_COOKIE message:', message.data)
+ const senderId = sender?.id
721
+ if (!senderId || senderId !== Browser.runtime.id) {
722
+ console.warn('[background] Rejecting GET_COOKIE message from untrusted sender:', sender)
723
+ return null
724
+ }
725
+
726
+ console.debug('[background] Processing GET_COOKIE message for:', message.data?.url)
727
try {
728
const cookie = await Browser.cookies.get({
729
url: message.data.url,
0 commit comments