windowPostMessageTransport throws when an unrelated postMessage has null data
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 74/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- typescript
调研方向
找到 getWindowPostMessageTransport 的实现,并检查由 connect() 安装的消息监听器。使用 data 为 null 或 undefined 的消息事件重现该问题,然后验证非对象 payload 会被忽略,同时现有的 target、stream、origin 和 MetaMask 消息处理保持不变。
由索引模型根据 Issue 内容生成。
描述
What happened?
getWindowPostMessageTransport().connect() installs a global window.addEventListener('message', ...) listener. That listener receives every postMessage on the page, including messages sent by unrelated scripts or iframes.
The current listener destructures event.data before validating it:
const { target, data } = event.data;
If another page script sends a valid postMessage with null or undefined data, this throws a TypeError before the listener can ignore the unrelated message.
Minimal reproduction
After connect() has registered the message listener, dispatching a message shaped like this is enough to trigger the crash:
messageHandler({
data: null,
origin: location.origin,
} as MessageEvent);
Expected: unrelated/non-object message payloads are ignored, the same as wrong target/stream/origin messages.
Actual: the listener throws while destructuring event.data.
Suggested fix
Add a small guard before destructuring:
if (!event.data || typeof event.data !== 'object') {
return;
}
This keeps the existing MetaMask message handling unchanged while preventing unrelated page messages from surfacing avoidable listener errors.
- 主要语言
- TypeScript
- 星标
- 1
- 派生
- 4
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 没有贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
相似的 Issue
-
automated issue report
难度 2/5 1-3 小时 新手友好度 66/100
databendlabs/databend-docs#3511 ·
-
area/dashboard kind/bug QA/dev-automation
难度 2/5 1-3 小时 新手友好度 65/100
rancher/dashboard#19379 · 2 条评论 ·
维护者通常 5 天内回复
-
perf(core): getComments() runs the approved count and the comment list as two sequential queries未关闭area/core bot:bug bot:working
难度 2/5 1-3 小时 新手友好度 76/100
emdash-cms/emdash#3905 · 2 条评论 ·
维护者通常 1 天内回复
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
难度 1/5 1 小时以内 新手友好度 90/100
lingdojo/kana-dojo#31728 · 1 条评论 · 5 个 reaction ·
维护者通常 1 天内回复
-
selective-claw: freshTailTurns=0 keeps ALL turns verbatim and summarizes none (slice(-0) === slice(0))可能已有人在做 @zjncs 今天认领。 未关闭component:tokenless
难度 2/5 1-3 小时 新手友好度 80/100
agentic-os-org/ANOLISA#6112 · 1 条评论 ·
维护者通常 1 天内回复