Repository navigation
Conversation
| event.waitUntil(self.clients.claim()) | ||
| }) | ||
|
|
||
| self.addEventListener('message', async function (event) { |
Check warning
Code scanning / CodeQL
Missing origin verification in `postMessage` handler Medium
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 13 days ago
Add an early allowlist check for event.origin in the message event listener before any command processing.
Best minimal fix (without changing existing functionality): compare event.origin against self.location.origin and return early when it does not match. This preserves current behavior for same-origin clients and rejects unexpected cross-origin message events.
Change required in:
examples/web-eid-angular-example/public/mockServiceWorker.js- Inside the
self.addEventListener('message', async function (event) { ... })block, immediately after entering the handler (before usingevent.source.id), add:- Guard for missing/invalid
event.origin - Equality check to
self.location.origin - Early
returnon mismatch
- Guard for missing/invalid
- Inside the
No new imports or dependencies are needed.
| @@ -24,6 +24,10 @@ | ||
| }) | ||
|
|
||
| self.addEventListener('message', async function (event) { | ||
| if (!event.origin || event.origin !== self.location.origin) { | ||
| return | ||
| } | ||
|
|
||
| const clientId = event.source.id | ||
|
|
||
| if (!clientId || !self.clients) { |
| event.waitUntil(self.clients.claim()) | ||
| }) | ||
|
|
||
| self.addEventListener('message', async function (event) { |
Check warning
Code scanning / CodeQL
Missing origin verification in `postMessage` handler Medium
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 13 days ago
Add an explicit origin verification at the start of the "message" event handler, before using event.source/event.data.
Best fix here: compare event.origin against the service worker’s own origin (self.location.origin) and return early if it does not match.
Edit in:
examples/web-eid-react-example/public/mockServiceWorker.js- Region around line 26 (
self.addEventListener('message', async function (event) { ... })
No new imports or dependencies are required.
| @@ -24,6 +24,10 @@ | ||
| }) | ||
|
|
||
| self.addEventListener('message', async function (event) { | ||
| if (event.origin !== self.location.origin) { | ||
| return | ||
| } | ||
|
|
||
| const clientId = event.source.id | ||
|
|
||
| if (!clientId || !self.clients) { |
4bc68b2 to
dac3b2e
Compare
c55532a to
9f20112
Compare
9f20112 to
8bf6e44
Compare
554ec5f to
4df7ceb
Compare
WE2-968 Signed-off-by: Tanel Metsar <taneltm@users.noreply.github.com>
WE2-968 Signed-off-by: Tanel Metsar <taneltm@users.noreply.github.com>
WE2-1179 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-1179 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-1179 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-1179 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com> Co-authored-by: TanelTM <taneltm@users.noreply.github.com>
WE2-1179 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-1179 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-1179 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-968 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-968 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-1240 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-1240 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
45409fa to
ea6d72c
Compare
WE2-1240 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
ea6d72c to
4615648
Compare
…exclude collisions WE2-1240 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-968
Supersedes #58
Closes #58