Commit b1beb5f
committed
fix(uxp): ship hygiene — gate udt-smoke.js, restrict postMessage, block exec shim
- Gate udt-smoke.js behind localStorage opencut_debug=1 so the mutating
test harness doesn't load in every production session
- Restrict postMessage targetOrigin from "*" to window.location.origin
- Block cep_node child_process.exec passthrough in the WebView shim
(was an open shell execution path)1 parent 199eec0 commit b1beb5f
2 files changed
Lines changed: 9 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
48 | 48 | | |
49 | 49 | | |
50 | 50 | | |
| 51 | + | |
51 | 52 | | |
52 | 53 | | |
53 | | - | |
| 54 | + | |
54 | 55 | | |
55 | 56 | | |
56 | 57 | | |
| |||
159 | 160 | | |
160 | 161 | | |
161 | 162 | | |
162 | | - | |
163 | | - | |
164 | | - | |
165 | | - | |
| 163 | + | |
| 164 | + | |
166 | 165 | | |
167 | 166 | | |
168 | 167 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1650 | 1650 | | |
1651 | 1651 | | |
1652 | 1652 | | |
1653 | | - | |
| 1653 | + | |
| 1654 | + | |
| 1655 | + | |
| 1656 | + | |
| 1657 | + | |
1654 | 1658 | | |
1655 | 1659 | | |
0 commit comments