Is WebChatGPT: Prompt library with web access safe?
WebChatGPT is medium risk. The extension ships a request-header rule for XHR/WebSocket requests matching bing.com. When it applies, the browser sets Origin and Referer to www.bing.com, so the receiving service sees Bing as the origin instead of the actual page.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Bing requests use Bing as Origin and Referer
The extension ships a request-header rule for XHR/WebSocket requests matching bing.com.
When it applies, the browser sets Origin and Referer to www.bing.com, so the receiving service sees Bing as the origin instead of the actual page.
The extension sends an XHR or WebSocket request to a bing.com URL.
The browser applies the extension rule and sends the request with Bing listed as both origin and referrer.
| Field | Value | Why it matters | |
|---|---|---|---|
Declared origin | Origin: https://www.bing.com | This tells the receiving service which site the browser says the request came from. | |
Declared referrer | Referer: https://www.bing.com | This tells the receiving service which page the browser says referred the request. | |
Covered request types | resourceTypes: xmlhttprequest, websocket | The rule applies to background data requests and WebSocket connections rather than ordinary page images or documents. |
Static request-header rule for bing.com
{
id: 1,
priority: 1,
action: {
type: "modifyHeaders",
requestHeaders: [
{
header: "origin",
operation: "set",
value: "https://www.bing.com"
},
{
header: "referer",
operation: "set",
value: "https://www.bing.com"
}
]
},
condition: {
urlFilter: "bing.com",
isUrlFilterCaseSensitive: false,
resourceTypes: ["xmlhttprequest", "websocket"]
}
}- bing.com
Any matching XHR or WebSocket request to this host receives Origin and Referer values set to https://www.bing.com.