Skip to content

[preview] 验证并隔离导入游戏对同源编辑器的访问 #6

Description

@jamiesun

Context Boundary

  • Repo/module: talkincode/GameKit, ZIP import and Pygame preview
  • Version/commit: main, 9eb811e7bc3db3193b57609425723c478e438d32
  • Runtime: imported project code runs in a same-origin /play/<session>/ iframe
  • OS/browser: not recorded; browser proof of concept has not been run in this review
  • Dependencies/config: pygbag 0.9.3 runtime; no sandbox flag on the iframe

Expectation vs. Reality

Expected: A project imported from a ZIP is treated as untrusted code and cannot inspect or modify the GameKit editor page or its project storage when Run is pressed.

Actual: The preview iframe is same-origin and has no sandbox attribute. The pygbag template exposes platform.window.parent through its Python-to-JavaScript bridge for its own debug messages. Source inspection therefore indicates that project code may be able to reach the parent GameKit page and same-origin browser APIs. This is a security-boundary finding, not a confirmed production incident; a benign browser proof of concept is still needed.

Reproduction Path

  1. In a throwaway project with no personal data, add a benign probe that attempts to set platform.window.parent.document.title to GameKit preview probe.
  2. Run the project and check whether the parent page title changes.
  3. Record the browser/runtime result; do not test against real project data or send data to an external host.

Minimal reproduction:

import platform
platform.window.parent.document.title = "GameKit preview probe"

Blast Radius

  • Affected users/paths: users who run projects imported from untrusted ZIPs.
  • Frequency: only when potentially untrusted project code is executed.
  • Severity rationale: if the bridge is reachable from project code, the same-origin editor and locally stored projects may be exposed; recommend P1 pending browser validation and an explicit trust-model decision.
  • Workaround: only run source that the user trusts until isolation is verified.

Evidence

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions