Skip to content

Conversation

@khanti42
Copy link
Collaborator

@khanti42 khanti42 commented Jan 27, 2025

Closes: #1060

@khanti42 khanti42 marked this pull request as ready for review February 6, 2025 15:15
@khanti42 khanti42 requested review from a team and Montoya as code owners February 6, 2025 15:15
Copy link
Contributor

@Montoya Montoya left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

On this line: https://github.com/qubic/qubic-mm-snap/blob/main/src/index.js#L18 the Snap allows the origin of a request to be passed as a parameter in the request. This means any dapp can pretend to be any URL it wants? I could fire a request with the parameter "opensea.com" as the origin and it will make it look like the request is coming from opensea.com. Is that intentional? Seems like a security issue.

@khanti42
Copy link
Collaborator Author

They are preparing an update @Montoya to remove this as they don't use it anyway. Good catch!

@khanti42 khanti42 requested a review from Montoya February 24, 2025 13:25
@khanti42
Copy link
Collaborator Author

@Montoya here is the update to fix the mentioned security issue qubic/qubic-mm-snap@26a8772

@Mrtenz Mrtenz merged commit 70fcd86 into main Mar 6, 2025
17 checks passed
@Mrtenz Mrtenz deleted the newQubicConnect branch March 6, 2025 20:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[New Snap] QubicConnect

5 participants