Skip to content

Commit 74161ca

Browse files
Authorize GET_COOKIE sender
1 parent 7fcbb32 commit 74161ca

1 file changed

Lines changed: 7 additions & 1 deletion

File tree

src/background/index.mjs

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -688,7 +688,13 @@ Browser.runtime.onMessage.addListener(async (message, sender) => {
688688
}
689689
}
690690
case 'GET_COOKIE': {
691-
console.log('[background] Processing GET_COOKIE message:', message.data)
691+
const senderId = sender?.id
692+
if (!senderId || senderId !== Browser.runtime.id) {
693+
console.warn('[background] Rejecting GET_COOKIE message from untrusted sender:', sender)
694+
return null
695+
}
696+
697+
console.debug('[background] Processing GET_COOKIE message for:', message.data?.url)
692698
try {
693699
const cookie = await Browser.cookies.get({
694700
url: message.data.url,

0 commit comments

Comments
 (0)