Commit 729440c5 authored by Uzair Farooq's avatar Uzair Farooq
Browse files

Verify that the post message source origin us https://tails.boum.org

parent 597e28a9
......@@ -3,7 +3,7 @@ document.addEventListener("DOMContentLoaded", function() {
window.addEventListener("message", receiveMessage);
function receiveMessage(event) {
if (event.source !== window || !event.data) {
if (event.source !== window || event.origin !== "https://tails.boum.org" || !event.data) {
return;
}
if (event.data.action === "verifying") {
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment