Conversation
Code Review: Session Resurrection (Firefox Add-on)Executive SummaryThe "Session Resurrection" add-on provides a simple and useful functionality for saving and restoring browser sessions. However, the current implementation has several critical security vulnerabilities (HTML injection), privacy concerns (excessive permissions), and architectural weaknesses (non-persistent settings, storage pollution) that should be addressed before wider distribution or submission to AMO (Add-ons Mozilla). 1. Security & Privacy🚩 Critical: HTML Injection (XSS)In const $li = $(`
<li id="${key_id}" class="collection-item _cao_session_item">
<p class="_cao_session_item_label">${key}</p>
...
</li>
`);Impact: A user could accidentally or maliciously enter a session name containing 🚩 High: Excessive PermissionsThe "host_permissions": [
"<all_urls>"
]Impact: This permission allows the extension to read and modify data on every website the user visits. It triggers a high-risk warning during installation.
|
After doing these suggested improvements, here's what the review says: Summary
Changes
Verification
|
mainly AI slop - trying to get this up to date!