Skip to content

Audit and bound destination/asset data flowing from XDR into popup URL parameters #9

Description

@knytcomics-ui

Summary

background.ts:22-28 builds a URLSearchParams directly from decoded XDR data (destination, asset) with no length or charset validation before using it to construct the popup's chrome.windows.create URL.

Current Behavior / Relevant Code

  • src/background/background.ts:22-28.
  • src/decode/decodeTransaction.ts:15-19 (assetLabel) constructs ${asset.getCode()}:${asset.getIssuer()} from SDK values that are attacker-influenced (any dApp/transaction author controls asset codes).

Why This Matters

While Chrome extension URLs and React rendering aren't classically XSS-prone here, unbounded attacker-controlled strings in a URL can still cause practical problems (URL length limits, popup rendering breakage, log/analytics pollution if added later) and should be defensively bounded as a matter of hygiene for a security-focused extension.

Proposed Solution

  • Add explicit length caps and character-set validation for destination and asset before URL construction, truncating or rejecting rather than passing through unbounded.
  • Add unit tests feeding extractDestination/resolveOutcome adversarial asset codes (very long strings, control characters) and asserting the popup URL stays well-formed.

Acceptance Criteria

  • Oversized/malformed destination or asset strings can't produce a malformed or oversized popup URL.
  • Tests cover at least one adversarial input case.

Definition of Done

  • npm run lint, npm run typecheck, npm test, and npm run build all pass locally and in CI
  • New or changed behavior is covered by unit tests (and integration/E2E tests where the change touches interception, background messaging, or the popup)
  • Any user-facing or architectural change is reflected in README.md
  • No regressions to the existing test suite or existing tier/interception behavior

How to Claim This Issue (Application Process)

  1. Comment first. Post a short implementation plan on this issue — your proposed approach, the files you expect to touch, and any open questions — before writing code. This prevents duplicate effort and lets a maintainer flag concerns early, which matters especially for an issue at this complexity level.
  2. Wait for assignment. A maintainer will review your plan and assign the issue to you, typically within 48 hours. Please do not open a draft PR before you're assigned.
  3. Stay active. If there's no visible activity (commits or comments) for 10 days after assignment, the issue may be unassigned and reopened to other contributors.
  4. Submit a scoped PR. Reference this issue (Closes #<issue-number>), keep the diff scoped to the acceptance criteria above, and ensure all CI gates pass before requesting review.
  5. Engage with review. Respond to review feedback within a reasonable timeframe; PRs with no response after 7 days may be closed pending resubmission when you're ready to pick it back up.

Category: Security & Interception Robustness
Estimated effort: S (small, ~1-2 days)
Difficulty: Advanced — this issue assumes familiarity with the codebase's MV3 service-worker architecture, the Freighter interception protocol, and/or the Stellar SDK.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions