-
Notifications
You must be signed in to change notification settings - Fork 312
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
document.com_agilebits_onepassword_fill( raw_data ) is danger in some case #260
Comments
Hello @mala, Thanks for taking the time to write in for reporting this issue 👍 The issue that you discovered is in fact made out of two issues:
We’ve identified the fixes and are currently testing them in development. We’ll be sure to update you by commenting on this issue, and close it once the fix is out. Cheers! |
Hi, I think that defense on js side is meaningless, because there are other ways to get js arguments. It would be better to use a local variables. (if there are no reasons to use document's property)
|
Thanks so much, @mala! It took @radazzouz and me the better part of today fighting with our build process but I think we have a good solution. I've updated #261 with the latest changes. I would love if you could take a look and let us know your thoughts. |
@jxpx777 Thanks. |
Yes, that's right. On iOS, the domains list is handled by the app and not the JS. We can let you know when this is released so you can test further if you like. Jamie Phelps
|
ok, savedUrl and url also should be restricted, please take care. |
Thanks @mala! We are no longer sending the properties you mentioned ( Once again, thank you so much for the assist here! |
How to reproduce
example:
it is problem of js context.
js context of “stringByEvaluatingJavaScriptFromString” is like a bookmarklet.
I also tested on browser extension(chrome,firefox), content script of browser extension run at “isolated world” so browser extensions are maybe not affected.(I'm not investigating deeply)
The text was updated successfully, but these errors were encountered: