missing origin/source check on store.steampowered.com cache-invalidation postMessage listener
Nobody has claimed this yet.
Assessment
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Newbie friendliness
- 88/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- javascript
- Domain
- security
Research direction
Start with scripts/store/invalidate_cache.js:17-29 and compare its message listener with scripts/steamdb/global.js:25-30. Verify the existing MAIN-world sender and run the extension's relevant checks or a focused message-event test. Done means foreign-origin or foreign-source messages no longer trigger cache invalidation, while same-window messages still do.
Written by the indexing model from the issue text.
Description
Summary
scripts/store/invalidate_cache.js listens for window "message" events and, on receiving { type: 'steamdb:extension-invalidate-cache' }, forwards a privileged InvalidateCache request to the background service worker with no check on event.origin or event.source. Any foreign origin can window.open() a store.steampowered.com tab and postMessage() this trigger directly, wiping the extension's cached Steam user/library/family data.
The near-identical listener on steamdb.info (scripts/steamdb/global.js:25-30) correctly checks request.origin !== window.location.origin -- this copy of the same feature just forgot it.
Root cause
// scripts/store/invalidate_cache.js:17-29
window.addEventListener( 'message', ( request ) =>
{
if( request?.data && request.data.type === 'steamdb:extension-invalidate-cache' )
{
SendMessageToBackgroundScript( { contentScriptQuery: 'InvalidateCache' }, () => {} );
}
} );
No origin/source check. store.steampowered.com sets frame-ancestors 'none' (can't be iframed) but no Cross-Origin-Opener-Policy, so a window.open() popup retains a scriptable cross-origin opener relationship -- enough to reach this listener.
Proof of concept (live-verified)
Loaded the real unpacked extension in Chrome via Puppeteer/CDP, mapping store.steampowered.com and an unrelated attacker.example to local fixtures, observed the real background service worker's chrome.storage.local:
// on https://attacker.example/
window.__popup = window.open('https://store.steampowered.com/', 'victim');
window.__popup.postMessage({ type: 'steamdb:extension-invalidate-cache' }, '*');
BEFORE: {"userdata.cached":111111,"userfamilydata":"{\"seed\":true}"}
AFTER: {"userdata.cached":1789393938791,"userfamilydata":"{}"}
CACHE WAS INVALIDATED BY FORGED CROSS-ORIGIN MESSAGE
Impact
Low: only reachable privileged action is InvalidateCache() -- forces re-fetch of the user's own dynamicstore/userdata endpoint, minor nuisance DoS + transient loss of "already owned" highlighting. No data exfiltration (fetch targets Steam's own endpoint with credentials, response never reaches the attacker). No other contentScriptQuery is reachable through this listener.
Suggested fix
window.addEventListener( 'message', ( request ) =>
{
if( request.source !== window || request.origin !== window.location.origin )
{
return;
}
if( request?.data && request.data.type === 'steamdb:extension-invalidate-cache' )
{
...
Mirrors the already-correct pattern in scripts/steamdb/global.js; the MAIN-world sender already targets window.location.origin explicitly, so this has no functional downside.
This report was produced with AI assistance (Claude, Anthropic): manifest review, source tracing, and a live end-to-end Puppeteer/CDP proof-of-concept against the real unpacked extension.
- Dominant language
- JavaScript
- Stars
- 1.2k
- Forks
- 96
- PR merge metrics
- No merged PRs in 30d
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from SteamDatabase/BrowserExtension
-
bug
Difficulty 4/5 3-5 days Newbie friendliness 48/100
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 55/100
-
enhancement
Difficulty 4/5 3-5 days Newbie friendliness 52/100
SteamDatabase/BrowserExtension#279 · 1 comment · 3 reactions ·
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 52/100
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 62/100
All issues in SteamDatabase/BrowserExtension
Similar issues
-
Design only Leadership Survey SLFS
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
bcgov/digital-journeys#2293 ·
-
Toolkit
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
API Bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
ProjectSidewalk/SidewalkWebpage#5556 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
jessepollak/home#1454 ·
Maintainers usually reply within 1 day
-
Mend: dependency security vulnerability untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 64/100
opensearch-project/OpenSearch-Dashboards#12822 ·
Maintainers usually reply within 1 day