fix(bridge): pin the loopback token exemption to the extension's stable origin - #110
Open
chintoleung wants to merge 1 commit into
Open
chintoleung wants to merge 1 commit into
chintoleung wants to merge 1 commit into
Conversation
…le origin Any installed extension could bypass bearer-token auth by presenting its own chrome-extension:// Origin (prefix check). The exemption is now an exact-match allowlist: the shipped extension pins a manifest key so its Chromium id (ampcoeplakeelcoengijbfbhjnlbdign) is stable across machines and updates, and that single origin is trusted by default. Every other origin must present the token; origin trust never applies off loopback. Hardening from adversarial review: - trustedExtensionOrigins entries are validated (chrome-extension://<a-p 32> only) and the effective allowlist is logged at mount; [] is the explicit hardened mode. A web-origin entry would have re-granted the trust this change removes. - Docs state the real boundary: the manifest key is public, so the pin stops incidental cross-extension access, not deliberate key-cloning; hardened deployments pair the token. Loopback-terminating proxies (tailscale serve, ssh -L) documented. - Updating from pre-0.1.5 changes the extension id once (settings are per id): READMEs and both installers now say to re-enter a configured remote bridge address/token. Extension version bumped to 0.1.5. - Drift guard: a test fails if the manifest key ever hashes to anything but the pinned id; malformed keys are rejected, not munged. - e2e now proves the pin: real Chromium must derive the pinned id and accept a tokenless hello against the default allowlist (plus the paired-token path), with a locale-independent harness and loud skips.
chintoleung
force-pushed
the
fix/bridge-origin-pinning
branch
from
October 5, 2026 08:25
6c60644 to
a118d3a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #108
Problem
Any installed extension could bypass bearer-token auth by presenting its own
chrome-extension://Origin (prefix check inattach()).Approach
trustedExtensionOrigins); default is the shipped extension's id. Chromium derives an unpacked extension's id from the manifestkey, so this PR pins a committed key → stable idampcoeplakeelcoengijbfbhjnlbdignacross machines and updates. Unlisted origins — including other extensions — must present the token; origin trust never applies off loopback.trustedExtensionOriginsentries are validated (chrome-extension://<32-char a-p id>) and the effective allowlist is logged at mount.[]is the explicit hardened mode (token pairing only) for hostile-extension or loopback-proxy (tailscale serve,ssh -L) topologies.keyever hashes to anything but the pinned id.Boundary (documented)
The manifest key is public: the pin stops incidental cross-extension access, not deliberate key-cloning; origin checks bind browser contexts only. Hardened deployments set
trustedExtensionOrigins: []and pair the token.Testing
[]fail-closed, invalid config entries throw, key→id drift guard.Notes for review
index.tsconfig-route block) — resolution should keep this PR's wording; the widerconnect-srcin fix(browser): connect remote --host 0.0.0.0 bridge clients #100 does not weaken the allowlist (non-loopback always needs the token).中文摘要
回环免 token 从「任意 chrome-extension:// 前缀」改为精确 Origin 白名单:扩展固定 manifest
key,id 在各机器与升级间稳定,默认仅信任该 id;其余 Origin 一律携带 token。配置项含格式校验与启动日志,[]为加固模式。0.1.5 前版本升级时 id 会变更一次,需重新填写远程桥地址/token(README 与安装器已注明)。