fix(content): mask multi-token cc-* autocomplete values - #111
Open
chintoleung wants to merge 1 commit into
Open
chintoleung wants to merge 1 commit into
chintoleung wants to merge 1 commit into
Conversation
isSensitiveField matched the whole autocomplete attribute against
'cc-', so spec-valid token lists like 'section-checkout billing
cc-number' escaped masking whenever the field's id/name/aria-label was
neutral. Tokenize the attribute per the HTML autocomplete grammar
(case-insensitive, whitespace-separated) and flag any credit-card or
cc-* detail token.
Hardening from adversarial review: read the CONTENT attribute, not the
IDL property — Chrome's autocomplete getter is limited to known values
and returns '' for token lists it cannot parse ('cc-number foo',
'bogus cc-number'), so the IDL silently dropped markup the mask must
see. Tests set the content attribute like production markup, and one
guard emulates Chrome's blanked getter while the raw attribute carries
the tokens; multi-token, mixed-case, and non-cc lists are covered.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #109
Problem
isSensitiveField()matched the wholeautocompleteattribute withstartsWith('cc-'), so spec-valid token lists (section-checkout billing cc-number) escaped masking on neutral-named fields. Reading the IDL property also drops values Chrome's limited-to-known-values getter blanks (cc-number foo).Fix
Tokenize the content attribute per the HTML autocomplete grammar (case-insensitive, whitespace-separated) and flag
credit-cardor anycc-*token.Testing
Tests set the content attribute like production markup; one guard emulates Chrome's blanked IDL getter while the raw attribute carries the tokens. Multi-token, mixed-case, and non-cc lists covered; extension suite 398/398.
Notes
Merges cleanly alongside #94 (its
SENSITIVE_PATTERNSadditions and this tokenizer are complementary).中文摘要
按 HTML autocomplete 语法分词并读取 content attribute(Chrome 的 IDL getter 会把无法解析的 token 列表返回为空),
credit-card与任意cc-*token 一律掩码。