remove ability to inject arbitrary scripts
Stephanie Ding committed
Sep 10, 2019 at 18:06 UTC
8a6cd3cd12932e5c6dfea9529c8cbafb9be46445
3 files changed
+21
-5
packages/react-devtools-extensions/src/inject.js
+7
-2
@@ -2,8 +2,13 @@
2
3
export default function inject(scriptName: string, done: ?Function) {
4
const source = `
5
+ // the prototype stuff is in case document.createElement has been modified
6
(function () {
6
- window.postMessage({ source: 'react-devtools-inject-script', scriptName: "${scriptName}" }, "*");
7
+ var script = document.constructor.prototype.createElement.call(document, 'script');
8
+ script.src = "${scriptName}";
9
+ script.charset = "utf-8";
10
+ document.documentElement.appendChild(script);
11
+ script.parentNode.removeChild(script);
12
})()
13
`;
14
@@ -16,4 +21,4 @@ export default function inject(scriptName: string, done: ?Function) {
21
done();
22
}
23
});
19
-}
\ No newline at end of file
24
+}
packages/react-devtools-extensions/src/injectGlobalHook.js
+2
-2
@@ -31,10 +31,10 @@ window.addEventListener('message', function(evt) {
31
reactBuildType: evt.data.reactBuildType,
32
};
33
chrome.runtime.sendMessage(lastDetectionResult);
34
- } else if (evt.data.source === 'react-devtools-inject-script' && evt.data.scriptName) {
34
+ } else if (evt.data.source === 'react-devtools-inject-backend') {
35
//Inject the specified script
36
var script = document.constructor.prototype.createElement.call(document, 'script');
37
- script.src = evt.data.scriptName;
37
+ script.src = chrome.runtime.getURL('build/backend.js');
38
script.charset = "utf-8";
39
document.documentElement.appendChild(script);
40
script.parentNode.removeChild(script);
packages/react-devtools-extensions/src/main.js
+12
-1
@@ -135,7 +135,18 @@ function createPanelIfReactLoaded() {
135
136
// Initialize the backend only once the Store has been initialized.
137
// Otherwise the Store may miss important initial tree op codes.
138
- inject(chrome.runtime.getURL('build/backend.js'));
138
+ chrome.devtools.inspectedWindow.eval(
139
+ `window.postMessage({ source: 'react-devtools-inject-backend' });`,
140
+ function(response, error) {
141
+ if (error) {
142
+ console.log(error);
143
+ }
144
+
145
+ if (typeof done === 'function') {
146
+ done();
147
+ }
148
+ }
149
+ );
150
151
const viewElementSourceFunction = createViewElementSource(
152
bridge,