Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ability to Inject inpage.js on Approved Sites #5243

Closed
JoshuaCaputo opened this issue Sep 12, 2018 · 1 comment
Closed

Ability to Inject inpage.js on Approved Sites #5243

JoshuaCaputo opened this issue Sep 12, 2018 · 1 comment

Comments

@JoshuaCaputo
Copy link

What problem are you trying to solve?
When your MetaMask is unlocked, it is possible for the address you are currently using to be viewed by all the other tabs you have open in your web browser.

Describe the solution you'd like
In many web browsers, your are asked if you would like to send your location, receive notifications, etc., under site settings. Is it possible for the MetaMask extension to only inject it's scripts on approved domains, possibly with SSL authentication?

Additional context
I know, this may seem like a super-user feature. However, it does seem to clear up any mapping of public address by sites. I was thinking of making a separate extension to kill the injection of MetaMask on any site not in the list.

@bdresser
Copy link
Contributor

@JoshuaCaputo check out #714 and related issues; also check out https://github.com/ethereum/EIPs/blob/master/EIPS/eip-1102.md

First step is opt-in web3 injection (and address exposure) and from there we'll work on making it per-site. Closing this for now, holler if you have more questions!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants