Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New Qubic Connect #1024

Open
wants to merge 4 commits into
base: main
Choose a base branch
from
Open

New Qubic Connect #1024

wants to merge 4 commits into from

Conversation

khanti42
Copy link
Collaborator

@khanti42 khanti42 commented Jan 27, 2025

Closes: #1060

@khanti42 khanti42 marked this pull request as ready for review February 6, 2025 15:15
@khanti42 khanti42 requested review from Montoya and a team as code owners February 6, 2025 15:15
Copy link
Contributor

@Montoya Montoya left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

On this line: https://github.com/qubic/qubic-mm-snap/blob/main/src/index.js#L18 the Snap allows the origin of a request to be passed as a parameter in the request. This means any dapp can pretend to be any URL it wants? I could fire a request with the parameter "opensea.com" as the origin and it will make it look like the request is coming from opensea.com. Is that intentional? Seems like a security issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[New Snap] QubicConnect
2 participants