From 4754fb948b4212df8908b1c62cd3ae945cecd9d3 Mon Sep 17 00:00:00 2001 From: Local Dev Date: Thu, 24 Sep 2026 22:50:36 +0200 Subject: [PATCH] =?UTF-8?q?fix(aegis):=200.9.9=20=E2=80=94=20keep=20the=20?= =?UTF-8?q?dapp=20bridge=20off=20Trusted-Types=20sites?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The main-world bridge was pushed into every https page as a text script. Sites that enforce Trusted Types refuse that and report the attempt to their CSP endpoint — Google's sign-in pages among them, which then have every reason to call the browser insecure. No dapp lives on those origins: a static list of the big enforcing sites is skipped outright, any other origin that rejects the bridge once is remembered and skipped from then on, and where Trusted Types exist unenforced a policy keeps the assignment clean. --- bundled-addons/aegis/addon.json | 2 +- bundled-addons/aegis/wallet-inject.js | 40 ++++++++++++++++++++++----- 2 files changed, 34 insertions(+), 8 deletions(-) diff --git a/bundled-addons/aegis/addon.json b/bundled-addons/aegis/addon.json index b96c7eb5..7f03d099 100644 --- a/bundled-addons/aegis/addon.json +++ b/bundled-addons/aegis/addon.json @@ -1,7 +1,7 @@ { "id": "aegis", "name": "Aegis Wallet", - "version": "0.9.8", + "version": "0.9.9", "category": "plugin", "description": "Multi-chain wallet (BCH, BTC, TRX, ETH, SOL, SC, DGB) derived from your Theseus vault. Dapps get window.bitcoincash on .x sites; window.tronWeb / window.tronLink / window.ethereum / window.solana on any https page.", "author": "Silent Mode", diff --git a/bundled-addons/aegis/wallet-inject.js b/bundled-addons/aegis/wallet-inject.js index 0287e5c5..62a93da4 100644 --- a/bundled-addons/aegis/wallet-inject.js +++ b/bundled-addons/aegis/wallet-inject.js @@ -543,11 +543,37 @@ const mainWorldSource = `(function () { // Actually push the script into the main world. Doing this at // document_start (which is when this preload runs) means the bridge is in // place before the dapp's own scripts execute. -try { - const s = document.createElement("script"); - s.textContent = mainWorldSource; - (document.head || document.documentElement).appendChild(s); - s.remove(); -} catch (e) { - console.warn("[aegis] main-world bridge install failed:", e && e.message || e); +// +// Sites that enforce Trusted Types (CSP `require-trusted-types-for 'script'`) +// refuse a text script AND report the attempt to their CSP endpoint. Google's +// sign-in pages do exactly that, and a "something injected a script into our +// login page" report is a fine reason for them to call the browser insecure. +// No dapp lives on those origins, so the bridge stays out: a static list for +// the big enforcing sites (no report at all), plus a per-origin memory for +// any other site that rejected us once (one report, never again). +const NO_BRIDGE_HOSTS = /(^|\.)(google\.[a-z.]+|googleapis\.com|gstatic\.com|youtube\.com|googleusercontent\.com|microsoftonline\.com|microsoft\.com|live\.com|office\.com|github\.com|apple\.com|icloud\.com)$/i; +function bridgeAllowedHere() { + try { + if (NO_BRIDGE_HOSTS.test(location.hostname)) return false; + if (localStorage.getItem("aegis:bridge-blocked") === "1") return false; + } catch {} + return true; +} +if (bridgeAllowedHere()) { + try { + let src = mainWorldSource; + // Where Trusted Types exist but are not enforced, a policy keeps the + // assignment clean; where they are enforced with an allow-list the + // policy call itself throws and we fall through to the plain string. + if (window.trustedTypes && typeof window.trustedTypes.createPolicy === "function") { + try { src = window.trustedTypes.createPolicy("aegis-bridge", { createScript: (x) => x }).createScript(mainWorldSource); } catch {} + } + const s = document.createElement("script"); + s.textContent = src; + (document.head || document.documentElement).appendChild(s); + s.remove(); + } catch (e) { + try { localStorage.setItem("aegis:bridge-blocked", "1"); } catch {} + console.warn("[aegis] main-world bridge install failed (this origin is now skipped):", e && e.message || e); + } }