Conversation
These endpoints were unauthenticated, allowing any local process to read browser refs, current URL, and command activity history. The wildcard Access-Control-Allow-Origin headers also allowed web pages to read the responses via cross-origin fetch. Now all three endpoints require the same bearer token used by sidebar endpoints, with a query-parameter fallback for EventSource (which cannot set custom headers). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Verifies that unauthenticated requests return 401 and that Access-Control-Allow-Origin: * is no longer present on responses. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
|
Good call gating these endpoints behind auth. The query param fallback for EventSource is a reasonable tradeoff since SSE clients can't set custom headers. Worth noting: the token in the URL will show up in server access logs and potentially in referrer headers if the page navigates. If that's a concern, you could rotate the token periodically or add a short-lived session mechanism. |
Contributor
|
@16francej Please close this PR. The affected browser endpoints were secured more safely in #595 and later hardening. This old version can put auth tokens in URLs, where they may leak into logs, so it must not be merged. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
/refs,/activity/stream, and/activity/historyendpoints — previously any local process or website could read browse state without authenticationAccess-Control-Allow-Origin: *headers from those endpoints so web pages can no longer read responses via cross-origin fetchvalidateAuthforEventSourcecompatibility (it cannot set custom headers)background.js,sidepanel.js) to pass auth tokens on all three endpointsTest plan
browse/test/endpoint-auth.test.ts— 12 tests covering all three endpointsAccess-Control-Allow-Originheader is absent from authenticated responsessidebar-integration.test.tsstill passes (13/13)activity.test.tsstill passes (18/18)🤖 Generated with Claude Code