chore: connection updates and improvements #24215
Merged
+368
−2
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Changelog
CHANGELOG entry:
Related issues
Fixes:
Manual testing steps
Screenshots/Recordings
Before
After
Pre-merge author checklist
Pre-merge reviewer checklist
Note
Adds origin validation to block connections/sessions when origin/title/url equals
metamask, with comprehensive tests and WalletConnect handling.DeeplinkProtocolService.ts): InsetupBridge, reject clients whoseoriginatorInfo.urlortitleequalsORIGIN_METAMASK.handlers/setupBridge.ts): Same exact-match rejection before creatingBackgroundBridge.services/connection-registry.ts): InhandleConnectDeeplink, block requests whenmetadata.dapp.urlornameequalsORIGIN_METAMASK.WalletConnectV2.ts):peer.metadata.url === ORIGIN_METAMASK.metadata.urlequalsORIGIN_METAMASK.metamaskorigin and allowing valid URLs/substrings in:DeeplinkProtocolService.test.ts,handlers/setupBridge.test.ts,services/connection-registry.test.ts, andWalletConnectV2.test.ts.ORIGIN_METAMASKwhere needed.Written by Cursor Bugbot for commit bc90da8. This will update automatically on new commits. Configure here.