@samitouri / QOS-React-2 / commits / 8a6cd3cd12

remove ability to inject arbitrary scripts

Stephanie Ding committed Sep 10, 2019 at 18:06 UTC 8a6cd3cd12932e5c6dfea9529c8cbafb9be46445
3 files changed +21 -5
packages/react-devtools-extensions/src/inject.js
+7 -2
@@ -2,8 +2,13 @@
2
3 export default function inject(scriptName: string, done: ?Function) {
4 const source = `
5 + // the prototype stuff is in case document.createElement has been modified
6 (function () {
6 - window.postMessage({ source: 'react-devtools-inject-script', scriptName: "${scriptName}" }, "*");
7 + var script = document.constructor.prototype.createElement.call(document, 'script');
8 + script.src = "${scriptName}";
9 + script.charset = "utf-8";
10 + document.documentElement.appendChild(script);
11 + script.parentNode.removeChild(script);
12 })()
13 `;
14
@@ -16,4 +21,4 @@ export default function inject(scriptName: string, done: ?Function) {
21 done();
22 }
23 });
19 -}
\ No newline at end of file
24 +}
packages/react-devtools-extensions/src/injectGlobalHook.js
+2 -2
@@ -31,10 +31,10 @@ window.addEventListener('message', function(evt) {
31 reactBuildType: evt.data.reactBuildType,
32 };
33 chrome.runtime.sendMessage(lastDetectionResult);
34 - } else if (evt.data.source === 'react-devtools-inject-script' && evt.data.scriptName) {
34 + } else if (evt.data.source === 'react-devtools-inject-backend') {
35 //Inject the specified script
36 var script = document.constructor.prototype.createElement.call(document, 'script');
37 - script.src = evt.data.scriptName;
37 + script.src = chrome.runtime.getURL('build/backend.js');
38 script.charset = "utf-8";
39 document.documentElement.appendChild(script);
40 script.parentNode.removeChild(script);
packages/react-devtools-extensions/src/main.js
+12 -1
@@ -135,7 +135,18 @@ function createPanelIfReactLoaded() {
135
136 // Initialize the backend only once the Store has been initialized.
137 // Otherwise the Store may miss important initial tree op codes.
138 - inject(chrome.runtime.getURL('build/backend.js'));
138 + chrome.devtools.inspectedWindow.eval(
139 + `window.postMessage({ source: 'react-devtools-inject-backend' });`,
140 + function(response, error) {
141 + if (error) {
142 + console.log(error);
143 + }
144 +
145 + if (typeof done === 'function') {
146 + done();
147 + }
148 + }
149 + );
150
151 const viewElementSourceFunction = createViewElementSource(
152 bridge,