Skip to content

fix(content): mask multi-token cc-* autocomplete values - #111

Open
chintoleung wants to merge 1 commit into
omdsh-dev:mainfrom
chintoleung:fix/cc-autocomplete-masking
Open

chintoleung wants to merge 1 commit into
omdsh-dev:mainfrom
chintoleung:fix/cc-autocomplete-masking

Conversation

@chintoleung

Copy link
Copy Markdown
Contributor

Fixes #109

Problem

isSensitiveField() matched the whole autocomplete attribute with startsWith('cc-'), so spec-valid token lists (section-checkout billing cc-number) escaped masking on neutral-named fields. Reading the IDL property also drops values Chrome's limited-to-known-values getter blanks (cc-number foo).

Fix

Tokenize the content attribute per the HTML autocomplete grammar (case-insensitive, whitespace-separated) and flag credit-card or any cc-* token.

Testing

Tests set the content attribute like production markup; one guard emulates Chrome's blanked IDL getter while the raw attribute carries the tokens. Multi-token, mixed-case, and non-cc lists covered; extension suite 398/398.

Notes

Merges cleanly alongside #94 (its SENSITIVE_PATTERNS additions and this tokenizer are complementary).

中文摘要

按 HTML autocomplete 语法分词并读取 content attribute(Chrome 的 IDL getter 会把无法解析的 token 列表返回为空),credit-card 与任意 cc-* token 一律掩码。

isSensitiveField matched the whole autocomplete attribute against
'cc-', so spec-valid token lists like 'section-checkout billing
cc-number' escaped masking whenever the field's id/name/aria-label was
neutral. Tokenize the attribute per the HTML autocomplete grammar
(case-insensitive, whitespace-separated) and flag any credit-card or
cc-* detail token.

Hardening from adversarial review: read the CONTENT attribute, not the
IDL property — Chrome's autocomplete getter is limited to known values
and returns '' for token lists it cannot parse ('cc-number foo',
'bogus cc-number'), so the IDL silently dropped markup the mask must
see. Tests set the content attribute like production markup, and one
guard emulates Chrome's blanked getter while the raw attribute carries
the tokens; multi-token, mixed-case, and non-cc lists are covered.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Snapshot: payment fields with multi-token autocomplete are echoed unmasked

1 participant