diff --git a/bundled-addons/aegis/wallet-inject.js b/bundled-addons/aegis/wallet-inject.js index ce47ffdf..2e370b7c 100644 --- a/bundled-addons/aegis/wallet-inject.js +++ b/bundled-addons/aegis/wallet-inject.js @@ -560,14 +560,20 @@ const mainWorldSource = `(function () { // the big enforcing sites (no report at all), plus a per-origin memory for // any other site that rejected us once (one report, never again). const NO_BRIDGE_HOSTS = /(^|\.)(google\.[a-z.]+|googleapis\.com|gstatic\.com|youtube\.com|googleusercontent\.com|microsoftonline\.com|microsoft\.com|live\.com|office\.com|github\.com|apple\.com|icloud\.com)$/i; +// +// The memory used to be "aegis:bridge-blocked", set on ANY failure. The +// commonest failure was ours: this preload often runs before the page has an +// element, so the append threw on null and the origin lost the bridge +// for good. That key is ignored now; only a Trusted Types refusal is kept. +const BLOCKED_KEY = "aegis:bridge-blocked-tt"; function bridgeAllowedHere() { try { if (NO_BRIDGE_HOSTS.test(location.hostname)) return false; - if (localStorage.getItem("aegis:bridge-blocked") === "1") return false; + if (localStorage.getItem(BLOCKED_KEY) === "1") return false; } catch {} return true; } -if (bridgeAllowedHere()) { +function installBridge() { try { let src = mainWorldSource; // Where Trusted Types exist but are not enforced, a policy keeps the @@ -581,7 +587,26 @@ if (bridgeAllowedHere()) { (document.head || document.documentElement).appendChild(s); s.remove(); } catch (e) { - try { localStorage.setItem("aegis:bridge-blocked", "1"); } catch {} - console.warn("[aegis] main-world bridge install failed (this origin is now skipped):", e && e.message || e); + const msg = String(e && e.message || e); + if (/trusted/i.test(msg)) { + try { localStorage.setItem(BLOCKED_KEY, "1"); } catch {} + console.warn("[aegis] this site enforces Trusted Types; the wallet bridge stays off here:", msg); + } else { + console.warn("[aegis] main-world bridge install failed:", msg); + } + } +} +if (bridgeAllowedHere()) { + if (document.documentElement) installBridge(); + else { + // The parser inserts before it runs any page script, and + // observer callbacks run at the microtask checkpoint that precedes each + // parser-inserted script, so the bridge is still first. + const mo = new MutationObserver(() => { + if (!document.documentElement) return; + mo.disconnect(); + installBridge(); + }); + mo.observe(document, { childList: true }); } }