brave / brave/security-action

New ruleset for `ExposeInterfacesToRenderer` and `RegisterBrowserInterfaceBindersForFrame` in `brave-core`

Open
#424 1 comment 1 reaction 1 assignee Assigned to @thypon View on GitHub
enhancement
Dominant language
JavaScript
Stars
22
Forks
8
Avg merge
2d 6h
Merged PRs (30d)
40

Description

Ruleset Name: Browser to Renderer API Exposure Check

1. Rule 1: Identify Unnecessary API Exposure
Description: This rule checks if there are APIs in the browser process that are unnecessarily exposed to the renderer process. It does this by scanning the code for any instances of APIs that are not required by the renderer but are still accessible.

2. Rule 2: Check Renderer Code Accessing Mojom APIs
Description: This rule scans the renderer code for any instances where it accesses Mojom APIs. This is done to ensure that the renderer is not accessing any APIs that it should not have access to.

3. Rule 3: Check for Calls to `ExposeInterfacesToRenderer`
Description: This rule checks for any calls to the `ExposeInterfacesToRenderer` function. This function is used to expose interfaces to the renderer, and unnecessary calls to this function can lead to security risks.

4. Rule 4: Check for Calls to `RegisterBrowserInterfaceBindersForFrame`
Description: This rule checks for any calls to the `RegisterBrowserInterfaceBindersForFrame` function. This function is used to register interface binders for a frame in the browser, and unnecessary calls to this function can lead to security risks.

This ruleset is designed to ensure that the browser process does not expose any unnecessary APIs to the renderer process, and that the renderer process does not access any APIs that it should not have access to. This is crucial for maintaining the security and integrity of the system.

Cc @diracdeltas @bridiver

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.