Audit browser references and cap iframe grants - #897
Conversation
Deploying mouseterm with
|
| Latest commit: |
99da64a
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://e9ced30b.mouseterm.pages.dev |
| Branch Preview URL: | https://spec-cleanup-browser-local.mouseterm.pages.dev |
dormouse-bot
left a comment
There was a problem hiding this comment.
standalone/sidecar/clipboard-ops.js still has the inherited-grant gap this PR closes for captures. readClipboardImageAsFilePath creates its directory with fsp.mkdtemp(path.join(osModule.tmpdir(), 'dormouse-drops-')) followed by fsp.chmod?.(dir, 0o700), and the chmod does nothing on Windows. A pasted clipboard image therefore inherits the same Everyone grant this PR's rationale reproduced on capture directories. The comment this PR deletes from private-capture-dir.ts said the two paths "are meant to match", so the clipboard path now has the weaker guarantee. Fixing it would mean giving the CommonJS sidecar module access to ensurePrivateDirectory, so it may be better as a follow-up than as part of this PR.
dormouse-bot
left a comment
There was a problem hiding this comment.
The new Windows gap is recorded only in security-local.md → "Browser panes". It is missing from the published list in docs/specs/security.md → ## Known gaps. That list already holds this file's other Windows ACL gap ("Neither VS Code's peer-link token, its Tool trust receipts, nor the recovery.json beside them carries a Windows ACL applied by Dormouse"), so a reader of /security gets no sign that screenshots of an authenticated browser and pasted clipboard images inherit the temp parent's ACL. The fix is a bullet beside that one, linking ./security-local.md#browser-panes. That line is outside this PR's diff, so there's no inline suggestion; I can push the commit if you want it.
Superseded by the review on a later commit.
The PR added guards rejecting null, numbers, and arrays where the viewer socket, the agent-browser daemon stream, and CDP deliver a JSON record, plus three tests for them. Every sender of those messages is trusted (agent-browser, CDP, Dormouse's own host) and none sends a non-record, so the guards were speculative hardening. Restore the base parsing at those sites and drop the tests. The new Windows known gap on the public /security page and in security-local.md read as if screenshots and clipboard images were exposed by default. The default %TEMP% is per-user and private; the rationale reproduced the exposure only with a shared temp parent. Reword both entries to say the files inherit that ACL and are exposed only when %TEMP% (or the capture parent) is shared or loosened, and ratchet security-local.md's budget for the qualifier. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The browser reference overstated directory projection, provider state, URL cadence and Windows temporary-file permissions. Correct those contracts, use canonical provider/viewport/frame types, and move local lifecycle mechanics to code comments or keyed rationale.
Enforce the 32 published iframe-grant cap after asynchronous bind, stamp grants at insertion, and ignore non-record daemon/CDP/viewer JSON. These are small changes covered by existing suites. Windows captures and clipboard images retain inherited ACLs; the local-security spec states that gap.
Validation on the revised stack: 97 tests in the three affected suites; strict library types; VS Code and all sidecar host bundles; spec/public-doc lints. Browser budget drops 350 words. The broader browser suites passed earlier; native browser UI is not newly verified.
Stack: based on #895.
Trimmed in review. Dropped the non-record JSON guards and their tests: every sender (agent-browser, CDP, Dormouse's own host) is trusted and never sends a non-record. The new Windows ACL known gap now says it applies only when
%TEMP%(or the capture parent) is shared or loosened. The default per-user%TEMP%is private.🤖 Generated with Claude Code