You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A browser task can fill forms with a caller's facts (names, contact details, and under payment: fill_then_approve, card details) and then stops with a screenshot of that screen in TaskReport.artifacts (#60). TaskReport is confidential, so the screenshot's handle only reaches callers through a confidential frame. But the bytes are read with BrowserReadOutput, which is not a confidential member, so the image crosses the bus in ordinary frames.
The same is true of any BrowserScreenshot a caller takes of a page showing typed secrets.
Mark BrowserReadOutput#[tinybus(confidential)]. It's the simplest and safest shape. But every current plain call starts failing, so under the contract rules it's a major bump (3.0). The in-memory test bus can't attest a module, so tests would call the service directly.
Add a confidential ReadTaskArtifact member (minor bump), and read task artifacts only through it. Nothing breaks, but it adds a second way to read an output, and BrowserScreenshot outputs stay unprotected.
Mitigations already in place
Output ids are unguessable and expire after five minutes.
Problem
A browser task can fill forms with a caller's facts (names, contact details, and under
payment: fill_then_approve, card details) and then stops with a screenshot of that screen inTaskReport.artifacts(#60).TaskReportis confidential, so the screenshot's handle only reaches callers through a confidential frame. But the bytes are read withBrowserReadOutput, which is not a confidential member, so the image crosses the bus in ordinary frames.The same is true of any
BrowserScreenshota caller takes of a page showing typed secrets.Raised in review: #60 (comment)
Options
BrowserReadOutput#[tinybus(confidential)]. It's the simplest and safest shape. But every current plain call starts failing, so under the contract rules it's a major bump (3.0). The in-memory test bus can't attest a module, so tests would call the service directly.ReadTaskArtifactmember (minor bump), and read task artifacts only through it. Nothing breaks, but it adds a second way to read an output, andBrowserScreenshotoutputs stay unprotected.Mitigations already in place
TaskReport, never in aTaskView,AwaitTaskorListTasksreply.