Skip to content

Commit 669d77e

Browse files
Authorize GET_COOKIE sender
1 parent ce31305 commit 669d77e

1 file changed

Lines changed: 7 additions & 1 deletion

File tree

src/background/index.mjs

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -717,7 +717,13 @@ Browser.runtime.onMessage.addListener(async (message, sender) => {
717717
}
718718
}
719719
case 'GET_COOKIE': {
720-
console.log('[background] Processing GET_COOKIE message:', message.data)
720+
const senderId = sender?.id
721+
if (!senderId || senderId !== Browser.runtime.id) {
722+
console.warn('[background] Rejecting GET_COOKIE message from untrusted sender:', sender)
723+
return null
724+
}
725+
726+
console.debug('[background] Processing GET_COOKIE message for:', message.data?.url)
721727
try {
722728
const cookie = await Browser.cookies.get({
723729
url: message.data.url,

0 commit comments

Comments
 (0)