Skip to content

fix(frontend): silence Unchecked runtime.lastError from extension messaging callbacks - #2139

Merged
giladresisi merged 1 commit into
stagingfrom
fix/extension-unchecked-last-error
Sep 25, 2026
Merged

giladresisi merged 1 commit into
stagingfrom
fix/extension-unchecked-last-error

Conversation

@giladresisi

Copy link
Copy Markdown
Collaborator

What kind of change does this PR introduce?

Bug fix (frontend, browser extension messaging). The two chrome.runtime.sendMessage calls that talk to the Postiz browser extension, STORE_REFRESH_TOKEN in apps/frontend/src/components/launches/continue.integration.tsx and REMOVE_REFRESH_TOKEN in apps/frontend/src/components/launches/menu/menu.tsx, passed a no-op callback. The callbacks now read chrome.runtime.lastError, matching the existing PING / GET_COOKIES callbacks in add.provider.component.tsx. The messages, their payloads, when they are sent, and the surrounding try/catch guards are unchanged; the calls remain fire-and-forget with no toast or Sentry capture.

Why was this change needed?

When the extension is not installed, disabled, or the page origin is not in its externally_connectable list, Chrome fails the message and logs this to the user's browser console, once per channel connect and once per channel delete:

Unchecked runtime.lastError: Could not establish connection. Receiving end does not exist.

Chrome only emits that line when the callback does not read lastError. Since most users do not have the extension, this shows up as a red error in the console of ordinary sessions and muddies debugging. Reading lastError in the callback is the documented way to mark the error as handled.

Other information:

The third call site already does this, so this only brings the two remaining callbacks in line. Unrelated to the Sentry "Could not establish connection" issues on /launches and /auth, whose frames come from third-party injected scripts, not from these calls.

QA

  1. Run the frontend with EXTENSION_ID set to an extension id that is not installed in your Chrome profile (or to the real Postiz extension id with the extension disabled under chrome://extensions).
  2. Open DevTools console on the app and connect a channel through a provider flow that lands on the continue page.
  3. Expected: no Unchecked runtime.lastError: Could not establish connection line in the console (on main it appears once here).
  4. Open a channel's menu in the calendar sidebar and delete the channel.
  5. Expected: again no Unchecked runtime.lastError line (on main it appears once here too).
  6. Optional: enable the Postiz extension, repeat steps 2 and 4, and confirm in the extension's service worker console that the refresh token is still stored and removed.

Checklist:

Put a "X" in the boxes below to indicate you have followed the checklist;

  • I have read the CONTRIBUTING guide.
  • I have signed the Contributor License Agreement (CLA) (ICLA for individuals, CCLA for entities).
  • I confirm I have not used AI to submit this PR or generate code for it.
  • I checked that there were no similar issues or PRs already open for this.
  • This PR fixes just ONE issue
  • I have filled in the QA section above with real steps to verify this change.

🤖 Generated with Claude Code

…allbacks

The STORE_REFRESH_TOKEN and REMOVE_REFRESH_TOKEN calls to the Postiz
browser extension passed a no-op callback. When the extension is not
installed, disabled, or the origin is not allowed, Chrome logs
"Unchecked runtime.lastError: Could not establish connection. Receiving
end does not exist." to the user's console because nothing read
lastError. Reading it in the callback, as add.provider.component.tsx
already does, marks the error as checked and silences the log. The
calls stay fire-and-forget with no behavior change.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@postiz-contribution
postiz-contribution Bot changed the base branch from main to staging September 25, 2026 02:06
@strix-security

strix-security Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Strix Security Review

No security issues found.

Review summary

Reviewed the two-file diff to apps/frontend/src/components/launches/continue.integration.tsx and apps/frontend/src/components/launches/menu/menu.tsx. Both changes only replace a no-op chrome.runtime.sendMessage callback with one that reads chrome.runtime.lastError to suppress an Unchecked runtime.lastError console warning when the browser extension is absent or disabled. The message types, payloads, send conditions, and surrounding try/catch guards are unchanged, and the new callbacks still ignore messaging failures. No security-relevant data flow, authentication, authorization, or validation behavior is modified by this PR, and no security findings were identified.

Updated for 709e05b.


Reviewed by Strix
Re-run review · Configure security review settings

@postiz-contribution postiz-contribution Bot added the contribution:approved Approved contributor label Sep 25, 2026
@postiz-agent

postiz-agent Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@giladresisi
giladresisi added this pull request to the merge queue Sep 25, 2026
Merged via the queue into staging with commit 620ba4f Sep 25, 2026
12 checks passed
@giladresisi
giladresisi deleted the fix/extension-unchecked-last-error branch September 25, 2026 02:28
@giladresisi
giladresisi restored the fix/extension-unchecked-last-error branch September 25, 2026 02:53
@giladresisi
giladresisi deleted the fix/extension-unchecked-last-error branch September 25, 2026 04:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contribution:approved Approved contributor

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant