fix(aegis): 0.9.9 — keep the dapp bridge off Trusted-Types sites
The main-world bridge was pushed into every https page as a text script. Sites that enforce Trusted Types refuse that and report the attempt to their CSP endpoint — Google's sign-in pages among them, which then have every reason to call the browser insecure. No dapp lives on those origins: a static list of the big enforcing sites is skipped outright, any other origin that rejects the bridge once is remembered and skipped from then on, and where Trusted Types exist unenforced a policy keeps the assignment clean.
This commit is contained in:
parent
4c7d8e3f56
commit
4754fb948b
2 changed files with 34 additions and 8 deletions
|
|
@ -1,7 +1,7 @@
|
||||||
{
|
{
|
||||||
"id": "aegis",
|
"id": "aegis",
|
||||||
"name": "Aegis Wallet",
|
"name": "Aegis Wallet",
|
||||||
"version": "0.9.8",
|
"version": "0.9.9",
|
||||||
"category": "plugin",
|
"category": "plugin",
|
||||||
"description": "Multi-chain wallet (BCH, BTC, TRX, ETH, SOL, SC, DGB) derived from your Theseus vault. Dapps get window.bitcoincash on .x sites; window.tronWeb / window.tronLink / window.ethereum / window.solana on any https page.",
|
"description": "Multi-chain wallet (BCH, BTC, TRX, ETH, SOL, SC, DGB) derived from your Theseus vault. Dapps get window.bitcoincash on .x sites; window.tronWeb / window.tronLink / window.ethereum / window.solana on any https page.",
|
||||||
"author": "Silent Mode",
|
"author": "Silent Mode",
|
||||||
|
|
|
||||||
|
|
@ -543,11 +543,37 @@ const mainWorldSource = `(function () {
|
||||||
// Actually push the script into the main world. Doing this at
|
// Actually push the script into the main world. Doing this at
|
||||||
// document_start (which is when this preload runs) means the bridge is in
|
// document_start (which is when this preload runs) means the bridge is in
|
||||||
// place before the dapp's own scripts execute.
|
// place before the dapp's own scripts execute.
|
||||||
try {
|
//
|
||||||
const s = document.createElement("script");
|
// Sites that enforce Trusted Types (CSP `require-trusted-types-for 'script'`)
|
||||||
s.textContent = mainWorldSource;
|
// refuse a text script AND report the attempt to their CSP endpoint. Google's
|
||||||
(document.head || document.documentElement).appendChild(s);
|
// sign-in pages do exactly that, and a "something injected a script into our
|
||||||
s.remove();
|
// login page" report is a fine reason for them to call the browser insecure.
|
||||||
} catch (e) {
|
// No dapp lives on those origins, so the bridge stays out: a static list for
|
||||||
console.warn("[aegis] main-world bridge install failed:", e && e.message || e);
|
// the big enforcing sites (no report at all), plus a per-origin memory for
|
||||||
|
// any other site that rejected us once (one report, never again).
|
||||||
|
const NO_BRIDGE_HOSTS = /(^|\.)(google\.[a-z.]+|googleapis\.com|gstatic\.com|youtube\.com|googleusercontent\.com|microsoftonline\.com|microsoft\.com|live\.com|office\.com|github\.com|apple\.com|icloud\.com)$/i;
|
||||||
|
function bridgeAllowedHere() {
|
||||||
|
try {
|
||||||
|
if (NO_BRIDGE_HOSTS.test(location.hostname)) return false;
|
||||||
|
if (localStorage.getItem("aegis:bridge-blocked") === "1") return false;
|
||||||
|
} catch {}
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
if (bridgeAllowedHere()) {
|
||||||
|
try {
|
||||||
|
let src = mainWorldSource;
|
||||||
|
// Where Trusted Types exist but are not enforced, a policy keeps the
|
||||||
|
// assignment clean; where they are enforced with an allow-list the
|
||||||
|
// policy call itself throws and we fall through to the plain string.
|
||||||
|
if (window.trustedTypes && typeof window.trustedTypes.createPolicy === "function") {
|
||||||
|
try { src = window.trustedTypes.createPolicy("aegis-bridge", { createScript: (x) => x }).createScript(mainWorldSource); } catch {}
|
||||||
|
}
|
||||||
|
const s = document.createElement("script");
|
||||||
|
s.textContent = src;
|
||||||
|
(document.head || document.documentElement).appendChild(s);
|
||||||
|
s.remove();
|
||||||
|
} catch (e) {
|
||||||
|
try { localStorage.setItem("aegis:bridge-blocked", "1"); } catch {}
|
||||||
|
console.warn("[aegis] main-world bridge install failed (this origin is now skipped):", e && e.message || e);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue