Skip to content

fix: inherit nodeIntegrationInWorker from the embedder for <webview> and window.open - #52823

Merged
MarshallOfSound merged 1 commit into
mainfrom
fix/webview-inherit-node-integration-in-worker
Aug 15, 2026
Merged

MarshallOfSound merged 1 commit into
mainfrom
fix/webview-inherit-node-integration-in-worker

Conversation

@MarshallOfSound

Copy link
Copy Markdown
Member

The <webview> guest-inheritance list clamps a guest to be no less restricted than its embedder for nodeIntegration, contextIsolation, sandbox, and friends, but nodeIntegrationInWorker was missing — so a webpreferences="nodeIntegrationInWorker=1" attribute was honoured even when the embedder had it off. nodeIntegrationInWorker was also absent from getLastWebPreferences(), so the inheritance check had nothing to compare against.

  • Add nodeIntegrationInWorker to the inherited web preferences for <webview> (and the equivalent window.open list).
  • Emit nodeIntegrationInWorker from SaveLastPreferences() so it round-trips through getLastWebPreferences(), matching nodeIntegration.
  • Document the <webview> inheritance behaviour; add regression coverage.

Notes: <webview> and window.open now inherit nodeIntegrationInWorker from the embedder, consistent with the other Node and sandbox preferences.

@MarshallOfSound
MarshallOfSound requested a review from a team as a code owner August 15, 2026 21:20
@MarshallOfSound MarshallOfSound added semver/patch backwards-compatible bug fixes target/41-x-y PR should also be added to the "41-x-y" branch. target/42-x-y PR should also be added to the "42-x-y" branch. target/43-x-y PR should also be added to the "43-x-y" branch. target/44-x-y PR should also be added to the "44-x-y" branch. labels Aug 15, 2026
@electron-cation electron-cation Bot added the new-pr 🌱 PR opened recently label Aug 15, 2026
…and window.open

The list of security options a <webview> guest always inherits from its
embedder, and the equivalent list child windows inherit from their parent,
omitted nodeIntegrationInWorker. As a result the webpreferences attribute
could set nodeIntegrationInWorker on a guest whose embedder had it disabled,
giving the guest's dedicated workers a Node environment the embedder itself
did not grant (and, with an unsandboxed embedder, dropping the guest out of
the sandbox). Add nodeIntegrationInWorker to both inheritance lists so a
guest can never be less secure than its embedder for this option.
@MarshallOfSound
MarshallOfSound force-pushed the fix/webview-inherit-node-integration-in-worker branch from a278ce7 to f79f45b Compare August 15, 2026 21:35
@MarshallOfSound
MarshallOfSound enabled auto-merge (squash) August 15, 2026 21:49
@MarshallOfSound
MarshallOfSound merged commit 4188528 into main Aug 15, 2026
77 checks passed
@MarshallOfSound
MarshallOfSound deleted the fix/webview-inherit-node-integration-in-worker branch August 15, 2026 23:05
@release-clerk

release-clerk Bot commented Aug 15, 2026

Copy link
Copy Markdown

Release Notes Persisted

&lt;webview&gt; and window.open now inherit nodeIntegrationInWorker from the embedder, consistent with the other Node and sandbox preferences.

@trop

trop Bot commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

I have automatically backported this PR to "41-x-y", please check out #52829

@trop trop Bot removed the target/41-x-y PR should also be added to the "41-x-y" branch. label Aug 15, 2026
@trop

trop Bot commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

I have automatically backported this PR to "43-x-y", please check out #52830

@trop

trop Bot commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

I have automatically backported this PR to "42-x-y", please check out #52831

@trop

trop Bot commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

I have automatically backported this PR to "44-x-y", please check out #52832

@trop trop Bot added in-flight/43-x-y in-flight/42-x-y in-flight/44-x-y and removed target/43-x-y PR should also be added to the "43-x-y" branch. labels Aug 15, 2026
@trop trop Bot added merged/44-x-y PR was merged to the "44-x-y" branch. merged/42-x-y PR was merged to the "42-x-y" branch. merged/43-x-y PR was merged to the "43-x-y" branch. merged/41-x-y PR was merged to the "41-x-y" branch. and removed target/42-x-y PR should also be added to the "42-x-y" branch. target/44-x-y PR should also be added to the "44-x-y" branch. in-flight/44-x-y in-flight/42-x-y in-flight/43-x-y in-flight/41-x-y labels Aug 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

45-x-y merged/41-x-y PR was merged to the "41-x-y" branch. merged/42-x-y PR was merged to the "42-x-y" branch. merged/43-x-y PR was merged to the "43-x-y" branch. merged/44-x-y PR was merged to the "44-x-y" branch. new-pr 🌱 PR opened recently semver/patch backwards-compatible bug fixes

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

3 participants