Skip to content

Commit 69739bd

Browse files
Authorize GET_COOKIE sender
1 parent 0dbe283 commit 69739bd

1 file changed

Lines changed: 7 additions & 1 deletion

File tree

src/background/index.mjs

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -775,7 +775,13 @@ Browser.runtime.onMessage.addListener(async (message, sender) => {
775775
}
776776
}
777777
case 'GET_COOKIE': {
778-
console.log('[background] Processing GET_COOKIE message:', message.data)
778+
const senderId = sender?.id
779+
if (!senderId || senderId !== Browser.runtime.id) {
780+
console.warn('[background] Rejecting GET_COOKIE message from untrusted sender:', sender)
781+
return null
782+
}
783+
784+
console.debug('[background] Processing GET_COOKIE message for:', message.data?.url)
779785
try {
780786
const cookie = await Browser.cookies.get({
781787
url: message.data.url,

0 commit comments

Comments
 (0)