Skip to content

Run VSP HTTP requests on the main process. - #4040

Open
jholdstock wants to merge 1 commit into
decred:masterfrom
jholdstock:vsp-csrf
Open

Run VSP HTTP requests on the main process.#4040
jholdstock wants to merge 1 commit into
decred:masterfrom
jholdstock:vsp-csrf

Conversation

@jholdstock

@jholdstock jholdstock commented Sep 6, 2026

Copy link
Copy Markdown
Member

Previously VSP HTTP requests were executed on the renderer process. This is not good practice for electron apps beause this blocks the UI while the request is in progress. It also causes a Sec-Fetch-Site header to be added to the request because it is handled in the same way as a real Chromium browser.

This has become problematic since vspd now implements CSRF protection which inspects the Sec-Fetch-Site header. Subsequently the "Fetch VSP Ticket Status" button on the "Staking" > "Ticket Status" tab is now broken. Fortunately this is the only request made by Decrediton which is subject to CSRF protection (everything else goes through dcrwallet) so all other functionality is working. Ticket purchases, voting etc are unaffected.

This PR moves the HTTP requests to the main process using the same pattern already used for daemon/dcrlnd/dex/trezord requests. VSP HTTP requests are registered as handlers in main.development.js, and used by wallet/vsp.js by calling invoke(...) instead of via middleware.

Previously VSP HTTP requests were executed on the renderer process. This
is not good practice for electron apps beause this blocks the UI while
the request is in progress. It also causes a Sec-Fetch-Site header to be
added to the request because it is handled in the same way as a real
Chromium browser.

This has become problematic since vspd now implements CSRF protection
which inspects the Sec-Fetch-Site header. Subsequently the "Fetch VSP
Ticket Status" button on the "Staking" > "Ticket Status" tab is now
broken. Fortunately this is the only request made by Decrediton which is
subject to CSRF protection (everything else goes through dcrwallet) so
all other functionality is working. Ticket purchases, voting etc are
unaffected.

This PR moves the HTTP requests to the main process using the same
pattern already used for daemon/dcrlnd/dex/trezord requests. VSP HTTP
requests are registered as handlers in main.development.js, and used by
wallet/vsp.js by calling invoke(...) instead of via middleware.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant