Skip to content

Audit browser references and cap iframe grants - #897

Merged
nedtwigg merged 10 commits into
spec-cleanup-input-renderingfrom
spec-cleanup-browser-local
Oct 2, 2026
Merged

nedtwigg merged 10 commits into
spec-cleanup-input-renderingfrom
spec-cleanup-browser-local

Conversation

@nedtwigg

@nedtwigg nedtwigg commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

The browser reference overstated directory projection, provider state, URL cadence and Windows temporary-file permissions. Correct those contracts, use canonical provider/viewport/frame types, and move local lifecycle mechanics to code comments or keyed rationale.

Enforce the 32 published iframe-grant cap after asynchronous bind, stamp grants at insertion, and ignore non-record daemon/CDP/viewer JSON. These are small changes covered by existing suites. Windows captures and clipboard images retain inherited ACLs; the local-security spec states that gap.

Validation on the revised stack: 97 tests in the three affected suites; strict library types; VS Code and all sidecar host bundles; spec/public-doc lints. Browser budget drops 350 words. The broader browser suites passed earlier; native browser UI is not newly verified.

Stack: based on #895.

Trimmed in review. Dropped the non-record JSON guards and their tests: every sender (agent-browser, CDP, Dormouse's own host) is trusted and never sends a non-record. The new Windows ACL known gap now says it applies only when %TEMP% (or the capture parent) is shared or loosened. The default per-user %TEMP% is private.

🤖 Generated with Claude Code

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Deploying mouseterm with  Cloudflare Pages  Cloudflare Pages

Latest commit: 99da64a
Status: ✅  Deploy successful!
Preview URL: https://e9ced30b.mouseterm.pages.dev
Branch Preview URL: https://spec-cleanup-browser-local.mouseterm.pages.dev

View logs

@dormouse-bot dormouse-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

standalone/sidecar/clipboard-ops.js still has the inherited-grant gap this PR closes for captures. readClipboardImageAsFilePath creates its directory with fsp.mkdtemp(path.join(osModule.tmpdir(), 'dormouse-drops-')) followed by fsp.chmod?.(dir, 0o700), and the chmod does nothing on Windows. A pasted clipboard image therefore inherits the same Everyone grant this PR's rationale reproduced on capture directories. The comment this PR deletes from private-capture-dir.ts said the two paths "are meant to match", so the clipboard path now has the weaker guarantee. Fixing it would mean giving the CommonJS sidecar module access to ensurePrivateDirectory, so it may be better as a follow-up than as part of this PR.

Comment thread lib/src/host/iframe-proxy.ts
dormouse-bot
dormouse-bot previously approved these changes Oct 2, 2026
@nedtwigg nedtwigg changed the title Audit browser specs and secure capture and iframe grants Audit browser references and cap iframe grants Oct 2, 2026

@dormouse-bot dormouse-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The new Windows gap is recorded only in security-local.md → "Browser panes". It is missing from the published list in docs/specs/security.md → ## Known gaps. That list already holds this file's other Windows ACL gap ("Neither VS Code's peer-link token, its Tool trust receipts, nor the recovery.json beside them carries a Windows ACL applied by Dormouse"), so a reader of /security gets no sign that screenshots of an authenticated browser and pasted clipboard images inherit the temp parent's ACL. The fix is a bullet beside that one, linking ./security-local.md#browser-panes. That line is outside this PR's diff, so there's no inline suggestion; I can push the commit if you want it.

@dormouse-bot
dormouse-bot dismissed their stale review October 2, 2026 06:05

Superseded by the review on a later commit.

@nedtwigg
nedtwigg added this pull request to stack #896 October 2, 2026 13:23
The PR added guards rejecting null, numbers, and arrays where the viewer
socket, the agent-browser daemon stream, and CDP deliver a JSON record,
plus three tests for them. Every sender of those messages is trusted
(agent-browser, CDP, Dormouse's own host) and none sends a non-record, so
the guards were speculative hardening. Restore the base parsing at those
sites and drop the tests.

The new Windows known gap on the public /security page and in
security-local.md read as if screenshots and clipboard images were
exposed by default. The default %TEMP% is per-user and private; the
rationale reproduced the exposure only with a shared temp parent. Reword
both entries to say the files inherit that ACL and are exposed only when
%TEMP% (or the capture parent) is shared or loosened, and ratchet
security-local.md's budget for the qualifier.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@nedtwigg
nedtwigg merged commit 5ce9132 into main Oct 2, 2026
10 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants