Conversation
| event.waitUntil(self.clients.claim()) | ||
| }) | ||
|
|
||
| self.addEventListener('message', async function (event) { |
Check warning
Code scanning / CodeQL
Missing origin verification in `postMessage` handler Medium
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 1 day ago
Add an early allowlist check for event.origin in the message event listener before any command processing.
Best minimal fix (without changing existing functionality): compare event.origin against self.location.origin and return early when it does not match. This preserves current behavior for same-origin clients and rejects unexpected cross-origin message events.
Change required in:
examples/web-eid-angular-example/public/mockServiceWorker.js- Inside the
self.addEventListener('message', async function (event) { ... })block, immediately after entering the handler (before usingevent.source.id), add:- Guard for missing/invalid
event.origin - Equality check to
self.location.origin - Early
returnon mismatch
- Guard for missing/invalid
- Inside the
No new imports or dependencies are needed.
| @@ -24,6 +24,10 @@ | ||
| }) | ||
|
|
||
| self.addEventListener('message', async function (event) { | ||
| if (!event.origin || event.origin !== self.location.origin) { | ||
| return | ||
| } | ||
|
|
||
| const clientId = event.source.id | ||
|
|
||
| if (!clientId || !self.clients) { |
| event.waitUntil(self.clients.claim()) | ||
| }) | ||
|
|
||
| self.addEventListener('message', async function (event) { |
Check warning
Code scanning / CodeQL
Missing origin verification in `postMessage` handler Medium
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 1 day ago
Add an explicit origin verification at the start of the "message" event handler, before using event.source/event.data.
Best fix here: compare event.origin against the service worker’s own origin (self.location.origin) and return early if it does not match.
Edit in:
examples/web-eid-react-example/public/mockServiceWorker.js- Region around line 26 (
self.addEventListener('message', async function (event) { ... })
No new imports or dependencies are required.
| @@ -24,6 +24,10 @@ | ||
| }) | ||
|
|
||
| self.addEventListener('message', async function (event) { | ||
| if (event.origin !== self.location.origin) { | ||
| return | ||
| } | ||
|
|
||
| const clientId = event.source.id | ||
|
|
||
| if (!clientId || !self.clients) { |
4bc68b2 to
dac3b2e
Compare
c55532a to
9f20112
Compare
9f20112 to
8bf6e44
Compare
554ec5f to
4df7ceb
Compare
WE2-968 Signed-off-by: Tanel Metsar <taneltm@users.noreply.github.com>
WE2-968 Signed-off-by: Tanel Metsar <taneltm@users.noreply.github.com>
WE2-1179 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-1179 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-1179 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-1179 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com> Co-authored-by: TanelTM <taneltm@users.noreply.github.com>
WE2-1179 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-1179 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-1179 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-968 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-968 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-1240 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
WE2-1240 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
45409fa to
ea6d72c
Compare
WE2-1240 Signed-off-by: Sven Mitt <svenzik@users.noreply.github.com>
ea6d72c to
4615648
Compare
WE2-968
Supersedes #58
Closes #58