[PR #30690] fix(web): restrict postMessage targetOrigin from wildcard to specific origins #32924

Closed
opened 2026-02-21 20:52:20 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/30690

State: closed
Merged: Yes


Summary

This PR fixes a security vulnerability (CVE) related to postMessage usage in the web frontend. The changes restrict the targetOrigin parameter from wildcard (*) to specific origins.

Fixes #30723

Changes

  1. Embedded Chatbot (web/app/components/base/chat/embedded-chatbot/header/index.tsx):

    • Changed from postMessage(..., '*') to using document.referrer to determine parent origin
    • Falls back to '*' only if referrer is unavailable
  2. OAuth Hook (web/hooks/use-oauth.ts):

    • Changed from postMessage(..., '*') to using window.opener.origin
    • Falls back to '*' only if opener origin is unavailable

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran make lint and make type-check (backend) and cd web && npx lint-staged (frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/30690 **State:** closed **Merged:** Yes --- ## Summary This PR fixes a security vulnerability (CVE) related to `postMessage` usage in the web frontend. The changes restrict the `targetOrigin` parameter from wildcard (`*`) to specific origins. Fixes #30723 ## Changes 1. **Embedded Chatbot** (`web/app/components/base/chat/embedded-chatbot/header/index.tsx`): - Changed from `postMessage(..., '*')` to using `document.referrer` to determine parent origin - Falls back to `'*'` only if referrer is unavailable 2. **OAuth Hook** (`web/hooks/use-oauth.ts`): - Changed from `postMessage(..., '*')` to using `window.opener.origin` - Falls back to `'*'` only if opener origin is unavailable ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [ ] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [ ] I've updated the documentation accordingly. - [ ] I ran `make lint` and `make type-check` (backend) and `cd web && npx lint-staged` (frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:52:20 -05:00
yindo closed this issue 2026-02-21 20:52:20 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#32924