We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 0dbe283 commit 69739bdCopy full SHA for 69739bd
1 file changed
src/background/index.mjs
@@ -775,7 +775,13 @@ Browser.runtime.onMessage.addListener(async (message, sender) => {
775
}
776
777
case 'GET_COOKIE': {
778
- console.log('[background] Processing GET_COOKIE message:', message.data)
+ const senderId = sender?.id
779
+ if (!senderId || senderId !== Browser.runtime.id) {
780
+ console.warn('[background] Rejecting GET_COOKIE message from untrusted sender:', sender)
781
+ return null
782
+ }
783
+
784
+ console.debug('[background] Processing GET_COOKIE message for:', message.data?.url)
785
try {
786
const cookie = await Browser.cookies.get({
787
url: message.data.url,
0 commit comments