fix: prevent cross-origin replay - #129
Open
fainashalts wants to merge 2 commits into
Open
Conversation
fainashalts
marked this pull request as ready for review
July 30, 2026 21:55
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes INT-697 by preventing export bundles from being replayed across different embedding origins.
This change:
iframe-stamperversions below 2.1.0MessageChannelversus legacypostMessageusageCustomer Impact
For customers using
@turnkey/iframe-stamper >= 2.1.0, no API changes are required. On the first load after deployment, the previous global embedded key is replaced with a new key scoped to the customer’s origin.Bundles encrypted to the previous public key will no longer decrypt after this rotation. Any export operation in progress during deployment may need to be restarted.
Older iframe-stamper clients remain supported, but their embedded key is now tied to the lifetime of the iframe document. Reloading or recreating the iframe requires requesting a new export bundle.
Standalone use continues to persist an embedded key, scoped to the frame’s own origin.
Implementation Details
localStoragekeyconnect-src; the complete HTML-escaped endpoint is retained forsendBeacon.Testing
new test coverage:
postMessagetarget-origin behaviorMessagePortprecedence over legacy window messagingMessageChannelsource, origin, port, and race-condition testsmanually verified that two localhost parent origins receive different public keys and successfully complete their own export flows
validation completed: 67 Jest tests passing, ESLint passing, prettier check passing, production webpack build passing,
git diff --checkpassingRollout Notes
TURNKEY_TELEMETRY_ENDPOINTso we can track legacy client adoptionpostMessagecompatibility in a follow-up