-
Notifications
You must be signed in to change notification settings - Fork 5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Move phishing warning to the extension #4773
Comments
Issue Status: 1. Open 2. Started 3. Submitted 4. Done Work has been started. These users each claimed they can complete the work by 4 months, 1 week from now. 1) kelvintyb has started work. Can complete within the week Learn more on the Gitcoin Issue Details page. |
@kelvintyb Hello from Gitcoin Core - are you still working on this issue? Please submit a WIP PR or comment back within the next 3 days or you will be removed from this ticket and it will be returned to an ‘Open’ status. Please let us know if you have questions!
Funders only: Snooze warnings for 1 day | 3 days | 5 days | 10 days | 100 days |
@bdresser can I clarify if the specification for showing the phishing.html full page refers to showing it within popup.html or as a separate window using either tabs.create() or windows.create()? |
we want to redirect the blocked page to a full-screen version of the extension. no new tab. basically exactly the same as current behavior, except instead of hitting metamask.io/phishing.html the user sees the same page loaded from the extension. @alextsg anything to add? |
This task will look something like adding a component for the phishing warning page and its route to |
Thanks for the input guys :) Is this the intended behaviour? I'm doing it slightly differently from Alex's approach since it's redirecting the current window to a html page bundled in the extension itself (see the URL). Not exactly a full screen version of the popup.html, but I'm unsure if that really works for blocking interaction with the window. |
@kelvintyb this looks good to me. @alextsg? |
Issue Status: 1. Open 2. Started 3. Submitted 4. Done Work for 0.065 ETH (31.07 USD @ $477.97/ETH) has been submitted by: @bdresser please take a look at the submitted work:
|
@bdresser appreciate if you could accept this submission on gitcoin so the bounty can be completed. thanks! |
@kelvintyb done. sorry for the delay and thanks for your work! |
Bounty: rather than redirect users to our website to show the phishing warning, we should bundle the phishing page with the extension and show it full-page when the user hits a flagged site.
This prevents the small privacy leak for users hitting our site and also removes
phishing.html
as a target of attack.The text was updated successfully, but these errors were encountered: