diff --git a/bundled-addons/aegis/addon.json b/bundled-addons/aegis/addon.json index b96c7eb5..7f03d099 100644 --- a/bundled-addons/aegis/addon.json +++ b/bundled-addons/aegis/addon.json @@ -1,7 +1,7 @@ { "id": "aegis", "name": "Aegis Wallet", - "version": "0.9.8", + "version": "0.9.9", "category": "plugin", "description": "Multi-chain wallet (BCH, BTC, TRX, ETH, SOL, SC, DGB) derived from your Theseus vault. Dapps get window.bitcoincash on .x sites; window.tronWeb / window.tronLink / window.ethereum / window.solana on any https page.", "author": "Silent Mode", diff --git a/bundled-addons/aegis/wallet-inject.js b/bundled-addons/aegis/wallet-inject.js index 0287e5c5..62a93da4 100644 --- a/bundled-addons/aegis/wallet-inject.js +++ b/bundled-addons/aegis/wallet-inject.js @@ -543,11 +543,37 @@ const mainWorldSource = `(function () { // Actually push the script into the main world. Doing this at // document_start (which is when this preload runs) means the bridge is in // place before the dapp's own scripts execute. -try { - const s = document.createElement("script"); - s.textContent = mainWorldSource; - (document.head || document.documentElement).appendChild(s); - s.remove(); -} catch (e) { - console.warn("[aegis] main-world bridge install failed:", e && e.message || e); +// +// Sites that enforce Trusted Types (CSP `require-trusted-types-for 'script'`) +// refuse a text script AND report the attempt to their CSP endpoint. Google's +// sign-in pages do exactly that, and a "something injected a script into our +// login page" report is a fine reason for them to call the browser insecure. +// No dapp lives on those origins, so the bridge stays out: a static list for +// the big enforcing sites (no report at all), plus a per-origin memory for +// any other site that rejected us once (one report, never again). +const NO_BRIDGE_HOSTS = /(^|\.)(google\.[a-z.]+|googleapis\.com|gstatic\.com|youtube\.com|googleusercontent\.com|microsoftonline\.com|microsoft\.com|live\.com|office\.com|github\.com|apple\.com|icloud\.com)$/i; +function bridgeAllowedHere() { + try { + if (NO_BRIDGE_HOSTS.test(location.hostname)) return false; + if (localStorage.getItem("aegis:bridge-blocked") === "1") return false; + } catch {} + return true; +} +if (bridgeAllowedHere()) { + try { + let src = mainWorldSource; + // Where Trusted Types exist but are not enforced, a policy keeps the + // assignment clean; where they are enforced with an allow-list the + // policy call itself throws and we fall through to the plain string. + if (window.trustedTypes && typeof window.trustedTypes.createPolicy === "function") { + try { src = window.trustedTypes.createPolicy("aegis-bridge", { createScript: (x) => x }).createScript(mainWorldSource); } catch {} + } + const s = document.createElement("script"); + s.textContent = src; + (document.head || document.documentElement).appendChild(s); + s.remove(); + } catch (e) { + try { localStorage.setItem("aegis:bridge-blocked", "1"); } catch {} + console.warn("[aegis] main-world bridge install failed (this origin is now skipped):", e && e.message || e); + } }