Skip to content

CDP capture misses a CSS-masked secret field that is not laid out #100

Description

@morisil

Found in the review of the capture-live-form-state branch (live form state + secret redaction).

The CDP capture (SnapshotDom in markanywhere-browse/.../CapturePage.kt) recognises a field the page masks with -webkit-text-security only through the snapshot's computed styles, which DOMSnapshot.captureSnapshot reports for laid-out nodes only.
The in-page JS walker (ElementToSemanticEvents.kt) uses getComputedStyle, which also answers for an element without a box.

Scenario: a filled <input type="text" style="-webkit-text-security: disc"> (a PIN, an OTP) sits in a hidden wizard step, a collapsed accordion or an inactive tab panel.
It has no layout box, so masked = false in the CDP capture and its value lands in the dump, while the JS dump of the same page redacts it.

This breaks both the redaction promise and the rule that the two dump producers decide content through one shared function (FormControls.kt).

Possible fixes: read the style for not-laid-out text-entry controls separately (e.g. CSS.getComputedStyleForNode / one Runtime.callFunctionOn per such control), or treat a not-laid-out control's masking as unknown and redact conservatively when the markup gives a hint.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions