Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

windowPostMessageTransport throws when an unrelated postMessage has null data

Open Beginner friendly
#108 0 comments 0 reactions 0 assignees View on GitHub

@omerbek is already working on this.

Since Aug 25, 2026.

  • #109 by @omerbek — open

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
74/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
typescript
Domain
api, frontend

Research direction

Find the getWindowPostMessageTransport implementation and inspect the message listener installed by connect(). Reproduce the issue with a message event whose data is null or undefined, then verify that non-object payloads are ignored while existing target, stream, origin, and MetaMask message handling remain unchanged.

Written by the indexing model from the issue text.

Description

What happened?

getWindowPostMessageTransport().connect() installs a global window.addEventListener('message', ...) listener. That listener receives every postMessage on the page, including messages sent by unrelated scripts or iframes.

The current listener destructures event.data before validating it:

const { target, data } = event.data;

If another page script sends a valid postMessage with null or undefined data, this throws a TypeError before the listener can ignore the unrelated message.

Minimal reproduction

After connect() has registered the message listener, dispatching a message shaped like this is enough to trigger the crash:

messageHandler({
  data: null,
  origin: location.origin,
} as MessageEvent);

Expected: unrelated/non-object message payloads are ignored, the same as wrong target/stream/origin messages.

Actual: the listener throws while destructuring event.data.

Suggested fix

Add a small guard before destructuring:

if (!event.data || typeof event.data !== 'object') {
  return;
}

This keeps the existing MetaMask message handling unchanged while preventing unrelated page messages from surfacing avoidable listener errors.

Dominant language
TypeScript
Stars
1
Forks
4
PR merge metrics
No merged PRs in 30d

Getting set up

  • No Dockerfile or Docker Compose file
  • Has a pull request template
  • No contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.