Summary
isSensitiveField() (extensions/dsh-browser/src/content/privacy.ts) tests the whole autocomplete value with startsWith('cc-'). Per the HTML spec autocomplete is a space-separated token list, so real checkout markup like autocomplete="section-checkout billing cc-number" misses the check whenever the field's id/name/aria-label is neutral (e.g. id="field1" — note the name patterns don't include a bare /cc/ either).
Additionally, Chrome's autocomplete IDL getter is limited to known values and returns '' for token lists it cannot parse (cc-number foo, bogus cc-number), so reading el.autocomplete drops markup the mask must see. The raw content attribute does not.
Impact
Card numbers/CSC can reach the model unmasked — exactly what this module exists to prevent.
Suggested fix
Read el.getAttribute('autocomplete'), tokenize (case-insensitive, whitespace), and flag credit-card or any cc-* token. (Partially overlaps the pattern additions in #94 — that PR extends name-based heuristics; this fixes the autocomplete grammar.)
Summary
isSensitiveField()(extensions/dsh-browser/src/content/privacy.ts) tests the wholeautocompletevalue withstartsWith('cc-'). Per the HTML specautocompleteis a space-separated token list, so real checkout markup likeautocomplete="section-checkout billing cc-number"misses the check whenever the field's id/name/aria-label is neutral (e.g.id="field1"— note the name patterns don't include a bare/cc/either).Additionally, Chrome's
autocompleteIDL getter is limited to known values and returns''for token lists it cannot parse (cc-number foo,bogus cc-number), so readingel.autocompletedrops markup the mask must see. The raw content attribute does not.Impact
Card numbers/CSC can reach the model unmasked — exactly what this module exists to prevent.
Suggested fix
Read
el.getAttribute('autocomplete'), tokenize (case-insensitive, whitespace), and flagcredit-cardor anycc-*token. (Partially overlaps the pattern additions in #94 — that PR extends name-based heuristics; this fixes the autocomplete grammar.)