fix: enforce webview security prefs from main process#10172
Open
jackkav wants to merge 1 commit into
Open
Conversation
Add a will-attach-webview handler on mainBrowserWindow.webContents so that security-critical WebPreferences (nodeIntegration, preload, etc.) are pinned in the main process regardless of what the renderer supplies via the webpreferences attribute string. The renderer-supplied string is still parsed for the one user-controlled preference we trust (javascript on/off for HTML preview), but everything else is overridden: nodeIntegration=false, nodeIntegrationInSubFrames=false, allowRunningInsecureContent=false, disableDialogs=true.
✅ Circular References ReportGenerated at: 2026-06-26T13:03:38.617Z Summary
Click to view all circular references in PR (9)Click to view all circular references in base branch (9)Analysis✅ No Change: This PR does not introduce or remove any circular references. This report was generated automatically by comparing against the |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
will-attach-webviewhandler onmainBrowserWindow.webContentsinwindow-utils.tsWebPreferences(nodeIntegration,nodeIntegrationInSubFrames,allowRunningInsecureContent,preload,preloadURL) are now pinned in the main process and cannot be overridden by renderer-supplied attributeswebpreferencesstring is still parsed for the one pref we trust:javascript(controls JS execution in HTML response preview — a legitimate user setting)disableDialogs=trueis always enforced from main regardless of renderer inputBackground
window-utils.tsenableswebviewTag: truefor the main window (line 208).ResponseWebViewrenders untrusted response bodies inside a<webview>and sets prefs via a renderer-side string attribute (disableDialogs=true, javascript=yes/no). Without awill-attach-webviewguard, a renderer compromise could supply arbitrarywebpreferencesvalues (e.g.nodeIntegration=true, a custompreloadscript) and the main process would apply them. This change moves enforcement to the main process.Test plan
nodeIntegrationis stillfalsefor webviews (default Electron behaviour, now also explicitly enforced)