From 4410def18c03af1dfbd7271ce6a234331dfa4615 Mon Sep 17 00:00:00 2001 From: Derrick Hammer Date: Tue, 19 Sep 2023 21:46:32 -0400 Subject: [PATCH] fix: add check for new worker domains and ignore any origins from them --- src/messages.ts | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/src/messages.ts b/src/messages.ts index 2662c2b..81bd298 100644 --- a/src/messages.ts +++ b/src/messages.ts @@ -14,6 +14,10 @@ export async function handleIncomingMessage(event: MessageEvent) { return; } + if (event.origin.endsWith(".module.kernel.lumeweb.com")) { + return; + } + if (!("nonce" in event.data)) { (event.source as WindowProxy).postMessage( {