Use MessageSender.origin to check if sender is one of eligible clients.
When an extension message is received, we check `MessageSender.id` to disallow requests from unknown clients. Unfortunately, `MessageSender.id` is currently not trustworthy (issue 982361) and therefore this CL switches to using `MessageSender.origin` instead. Bug: 10321587 Change-Id: I3729a407bef47e5ca4212ee3fe748b89c8d16a50 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/2031526Reviewed-by:David Tseng <dtseng@chromium.org> Commit-Queue: Łukasz Anforowicz <lukasza@chromium.org> Cr-Commit-Position: refs/heads/master@{#737518}
Showing
Please register or sign in to comment