Screen picker: remove nodeIntegration and script-injected data #11
No reviewers
Labels
No labels
ai
ai:in-progress
ai:in-review
ai:merging
ai:needs-attention
cleanup
performance
security
severity/high
severity/low
severity/medium
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
adam/sunburn-desktop!11
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ai/issue-7"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes #7
src/picker.htmlwith a sandboxed, context-isolated preload (src/picker-preload.js) exposing onInit/select/cancel/listAudio. Window titles are sent over IPC and only rendered via textContent, so</script>in a title can no longer inject code.webContents.ipc(no accumulatingipcMain.oncelisteners; messages from other senders are ignored). Result resolves once on window close.showAudioOnlyPickerandgetPickerHTML.Testing:
node --checkon both JS files. Not run in Electron (no test framework; node_modules not installed). Manual check suggested: open a window titled</script><script>require('child_process')...and open the picker.Note: picker reuses the global
list-audio-sourceshandler; if #6 restricts IPC by origin, register it on the picker's webContents instead.WIP: Screen picker: remove nodeIntegration and script-injected datato Screen picker: remove nodeIntegration and script-injected data