-
Notifications
You must be signed in to change notification settings - Fork 207
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: Prevent a webpage document element to be detected as the Extension API object #153
Changes from 4 commits
c8cbd6e
57da1c3
a6f31b2
de4adf5
17536d2
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,20 @@ | ||
<!DOCTYPE> | ||
<html> | ||
<head> | ||
<title>Test Extension Background page</title> | ||
<meta charset="utf-8"> | ||
</head> | ||
<body> | ||
<!-- | ||
The following two DOM elements ensure that the polyfill doesn't detect the | ||
globals defined for these DOM element ids as the Extensions API objects. | ||
--> | ||
<div id="browser"></div> | ||
<div id="browser"></div> | ||
<div id="chrome"></div> | ||
|
||
<script src="copy-original-api-objects.js"></script> | ||
<script src="browser-polyfill.js"></script> | ||
<script src="background.js"></script> | ||
</body> | ||
</html> |
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,15 @@ | ||
/* global originalAPIObjects */ | ||
|
||
// Register an additional message handler that always reply after | ||
// a small latency time. | ||
browser.runtime.onMessage.addListener(async (msg, sender) => { | ||
if (msg !== "test-api-object-in-background-page") { | ||
return false; | ||
} | ||
|
||
return Promise.resolve({ | ||
browserIsDefined: !!browser, | ||
chromeIsDefined: !!chrome, | ||
browserIsUnchanged: browser === originalAPIObjects.browser, | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Let's check |
||
}); | ||
}); |
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,2 @@ | ||
// Store a copy of the references to the original API objects. | ||
const originalAPIObjects = {browser, chrome}; // eslint-disable-line no-unused-vars | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Add a comment that in browsers without a |
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -6,5 +6,13 @@ | |
</head> | ||
<body> | ||
<h1>Browser Polyfill Test Page</h1> | ||
|
||
<!-- | ||
The following two DOM elements ensure that the polyfill doesn't detect the | ||
globals defined for these DOM element ids as the Extensions API objects. | ||
--> | ||
<div id="browser"></div> | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Add another |
||
<div id="browser"></div> | ||
<div id="chrome"></div> | ||
</body> | ||
</html> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why
return false;
? If you don't want the handler to respond, jus return void (return;
).Or make this a non-async function and call
sendResponse({ ... });
in the end.