Screen picker: remove nodeIntegration and script-injected data #7
Labels
No labels
ai
ai:in-progress
ai:in-review
ai:merging
ai:needs-attention
cleanup
performance
security
severity/high
severity/low
severity/medium
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
adam/sunburn-desktop#7
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem: The picker window runs with
nodeIntegration: true, contextIsolation: false, and source names (window titles) are interpolated into a<script>viaJSON.stringify, which does not escape</script>.Impact: Any window title — e.g. a browser tab whose page sets
<title></script><script>require('child_process')…— breaks out of the script block when the picker opens → arbitrary code execution.Fix:
contextIsolation: true,nodeIntegration: false, small preload exposingselect/cancel/listAudio.loadFile+postMessage) instead of string-templating into the HTML.showAudioOnlyPicker(also buildsinnerHTMLfrom app names).ipcMain.once('picker-select'|'picker-cancel')leftovers when the window closes (they accumulate per open).Where:
src/picker.jsFixed by #11 (#11)