{"id":1444,"date":"2026-09-06T16:38:56","date_gmt":"2026-09-06T16:38:56","guid":{"rendered":"https:\/\/www.securesteps.tn\/?p=1444"},"modified":"2026-09-06T16:38:56","modified_gmt":"2026-09-06T16:38:56","slug":"perchance-nns-ctf-walkthrough","status":"publish","type":"post","link":"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/","title":{"rendered":"perchance \u2014 Browser Extension Origin and Context Confusion | NNS CTF"},"content":{"rendered":"<h1>perchance \u2014 Browser Extension Origin and Context Confusion<\/h1>\n<p><strong>Platform:<\/strong> NNS CTF 2026<br \/><strong>Category:<\/strong> Web \/ Browser Extension<\/p>\n<h2>1. Components<\/h2>\n<p>The challenge combines a bot, a browser extension, an attacker-controlled page, and the trusted Rust documentation origin. The goal is to make code execute in the Rust documentation origin, where a non-HttpOnly flag cookie is available.<\/p>\n<p>The exploit is not one isolated bug. It is a chain of trust failures: weak URL validation, an unvalidated cross-origin message, an attacker-observable imported function, and unsafe HTML insertion.<\/p>\n<h2>2. Weak URL validation<\/h2>\n<p>The options page accepts a URL only if it contains <code>https:\/\/doc.rust-lang.org\/<\/code>. This is a substring check, not an origin check. A URL using userinfo can satisfy the check while loading an attacker host, for example:<\/p>\n<pre><code>https:\/\/anything@ATTACKER\/?https:\/\/doc.rust-lang.org\/<\/code><\/pre>\n<p>The browser interprets <code>ATTACKER<\/code> as the real host; the Rust string appears only in the userinfo\/query portion. The code then stores <code>u.origin<\/code> as <code>activateOn<\/code>, allowing the attacker origin to become the extension&#8217;s activation origin.<\/p>\n<h2>3. Cross-origin postMessage bug<\/h2>\n<p>The options script listens for messages and calls <code>updateConfig<\/code> whenever the data begins with <code>http<\/code>. It never checks <code>event.origin<\/code> or that <code>event.source<\/code> is the expected window:<\/p>\n<pre><code>window.addEventListener('message', function (e) {\n  if (e.data.match(\/^https?\/)) updateConfig(e.data);\n});<\/code><\/pre>\n<p>An attacker page can frame the options page and post the crafted URL. This bypasses the need for a manual user entry and sets the extension configuration from an untrusted origin.<\/p>\n<h2>4. Replacing the sanitizer function<\/h2>\n<p>On an activated page, the content script creates a random name and injects a module import into the page context:<\/p>\n<pre><code>const nonce = 'a' + crypto.randomUUID().replaceAll('-', '');\nscr.textContent = `import ${nonce} from 'http:\/\/localhost:3000\/jsxss.js';\nwindow['${nonce}']=${nonce}`;<\/code><\/pre>\n<p>The script waits until <code>window.wrappedJSObject[nonce]<\/code> exists and then calls it on the current URL. The random name is not secret from page observers: a MutationObserver can watch newly inserted script elements, extract the nonce, and define the corresponding global before the import completes. The attacker-controlled replacement returns HTML instead of sanitized text.<\/p>\n<h2>5. Reaching the trusted origin<\/h2>\n<p>The content script stores the return value as <code>previous<\/code>. On the final visit it creates a paragraph and assigns:<\/p>\n<pre><code>elm.innerHTML = `Previous: ${prev}`;<\/code><\/pre>\n<p>Because the stored value can contain markup, an image payload such as an <code>onerror<\/code> handler executes when inserted. The final navigation is to <code>https:\/\/doc.rust-lang.org\/stable\/std\/<\/code>, so the payload runs where the flag cookie is readable and sends it to the attacker-controlled endpoint.<\/p>\n<h2>6. Exploit sequence<\/h2>\n<ol>\n<li>Frame the extension options page.<\/li>\n<li>Send an attacker URL containing the required Rust substring to set <code>activateOn<\/code>.<\/li>\n<li>Reload the attacker page so the content script executes.<\/li>\n<li>Observe the imported script, recover its random global name, and replace the sanitizer function.<\/li>\n<li>Return an HTML payload that exfiltrates <code>document.cookie<\/code>.<\/li>\n<li>Reset the activation origin to Rust documentation.<\/li>\n<li>Navigate to the Rust standard-library page and read the exfiltrated cookie.<\/li>\n<\/ol>\n<h2>7. Verified result<\/h2>\n<p>The bot requested an <code>\/exfil<\/code> URL containing the URL-encoded flag cookie. Decoding that value produced:<\/p>\n<pre><code>flag=NNS{p3RH4ps_y0u_M16h7_P0551b1Y_3Nj0Y_c7Fs_P3RCH4nc3}<\/code><\/pre>\n<h2>8. Defensive lessons<\/h2>\n<ul>\n<li>Compare parsed URL origins, not substrings.<\/li>\n<li>Validate both <code>event.origin<\/code> and <code>event.source<\/code> for postMessage.<\/li>\n<li>Do not expose security-sensitive functions through page globals.<\/li>\n<li>Keep extension data isolated from page scripts.<\/li>\n<li>Use text insertion or a trusted sanitizer instead of <code>innerHTML<\/code>.<\/li>\n<li>Mark sensitive cookies HttpOnly and Secure where possible.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Detailed NNS CTF browser-extension walkthrough covering URL validation, postMessage origin confusion, sanitizer replacement, trusted-origin execution, and defenses.<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_joinchat":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1444","post","type-post","status-publish","format-standard","hentry","category-webapplicationsecurity"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Detailed NNS CTF browser-extension walkthrough covering URL validation, postMessage origin confusion, sanitizer replacement, trusted-origin execution, and defenses.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Zied BELGHITH\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ar_AR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Secure Steps - Cybersecurity assessments, insights, and clear remediation.\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"perchance \u2014 Browser Extension Origin and Context Confusion | NNS CTF - Secure Steps\" \/>\n\t\t<meta property=\"og:description\" content=\"Detailed NNS CTF browser-extension walkthrough covering URL validation, postMessage origin confusion, sanitizer replacement, trusted-origin execution, and defenses.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-06T16:38:56+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-06T16:38:56+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:title\" content=\"perchance \u2014 Browser Extension Origin and Context Confusion | NNS CTF - Secure Steps\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Detailed NNS CTF browser-extension walkthrough covering URL validation, postMessage origin confusion, sanitizer replacement, trusted-origin execution, and defenses.\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/perchance-nns-ctf-walkthrough\\\/#blogposting\",\"name\":\"perchance \\u2014 Browser Extension Origin and Context Confusion | NNS CTF - Secure Steps\",\"headline\":\"perchance \\u2014 Browser Extension Origin and Context Confusion | NNS CTF\",\"author\":{\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/author\\\/zied_belhotmail-com\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/#organization\"},\"datePublished\":\"2026-09-06T16:38:56+00:00\",\"dateModified\":\"2026-09-06T16:38:56+00:00\",\"inLanguage\":\"ar\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/perchance-nns-ctf-walkthrough\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/perchance-nns-ctf-walkthrough\\\/#webpage\"},\"articleSection\":\"Web Application Security\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/perchance-nns-ctf-walkthrough\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/category\\\/webapplicationsecurity\\\/#listItem\",\"name\":\"Web Application Security\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/category\\\/webapplicationsecurity\\\/#listItem\",\"position\":2,\"name\":\"Web Application Security\",\"item\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/category\\\/webapplicationsecurity\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/perchance-nns-ctf-walkthrough\\\/#listItem\",\"name\":\"perchance \\u2014 Browser Extension Origin and Context Confusion | NNS CTF\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/perchance-nns-ctf-walkthrough\\\/#listItem\",\"position\":3,\"name\":\"perchance \\u2014 Browser Extension Origin and Context Confusion | NNS CTF\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/category\\\/webapplicationsecurity\\\/#listItem\",\"name\":\"Web Application Security\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/#organization\",\"name\":\"securesteps.tn\",\"description\":\"Cybersecurity assessments, insights, and clear remediation.\",\"url\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/author\\\/zied_belhotmail-com\\\/#author\",\"url\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/author\\\/zied_belhotmail-com\\\/\",\"name\":\"Zied BELGHITH\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/perchance-nns-ctf-walkthrough\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/96c18e9fc52e08c45006f84f0408ced54b58a24c6b0f5677185df3b75650034d?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Zied BELGHITH\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/perchance-nns-ctf-walkthrough\\\/#webpage\",\"url\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/perchance-nns-ctf-walkthrough\\\/\",\"name\":\"perchance \\u2014 Browser Extension Origin and Context Confusion | NNS CTF - Secure Steps\",\"description\":\"Detailed NNS CTF browser-extension walkthrough covering URL validation, postMessage origin confusion, sanitizer replacement, trusted-origin execution, and defenses.\",\"inLanguage\":\"ar\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/perchance-nns-ctf-walkthrough\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/author\\\/zied_belhotmail-com\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/author\\\/zied_belhotmail-com\\\/#author\"},\"datePublished\":\"2026-09-06T16:38:56+00:00\",\"dateModified\":\"2026-09-06T16:38:56+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/#website\",\"url\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/\",\"name\":\"Secure Steps\",\"description\":\"Cybersecurity assessments, insights, and clear remediation.\",\"inLanguage\":\"ar\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.securesteps.tn\\\/ar\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"perchance \u2014 Browser Extension Origin and Context Confusion | NNS CTF - Secure Steps","description":"Detailed NNS CTF browser-extension walkthrough covering URL validation, postMessage origin confusion, sanitizer replacement, trusted-origin execution, and defenses.","canonical_url":"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/#blogposting","name":"perchance \u2014 Browser Extension Origin and Context Confusion | NNS CTF - Secure Steps","headline":"perchance \u2014 Browser Extension Origin and Context Confusion | NNS CTF","author":{"@id":"https:\/\/www.securesteps.tn\/ar\/author\/zied_belhotmail-com\/#author"},"publisher":{"@id":"https:\/\/www.securesteps.tn\/ar\/#organization"},"datePublished":"2026-09-06T16:38:56+00:00","dateModified":"2026-09-06T16:38:56+00:00","inLanguage":"ar","mainEntityOfPage":{"@id":"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/#webpage"},"isPartOf":{"@id":"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/#webpage"},"articleSection":"Web Application Security"},{"@type":"BreadcrumbList","@id":"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.securesteps.tn\/ar#listItem","position":1,"name":"Home","item":"https:\/\/www.securesteps.tn\/ar","nextItem":{"@type":"ListItem","@id":"https:\/\/www.securesteps.tn\/ar\/category\/webapplicationsecurity\/#listItem","name":"Web Application Security"}},{"@type":"ListItem","@id":"https:\/\/www.securesteps.tn\/ar\/category\/webapplicationsecurity\/#listItem","position":2,"name":"Web Application Security","item":"https:\/\/www.securesteps.tn\/ar\/category\/webapplicationsecurity\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/#listItem","name":"perchance \u2014 Browser Extension Origin and Context Confusion | NNS CTF"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.securesteps.tn\/ar#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/#listItem","position":3,"name":"perchance \u2014 Browser Extension Origin and Context Confusion | NNS CTF","previousItem":{"@type":"ListItem","@id":"https:\/\/www.securesteps.tn\/ar\/category\/webapplicationsecurity\/#listItem","name":"Web Application Security"}}]},{"@type":"Organization","@id":"https:\/\/www.securesteps.tn\/ar\/#organization","name":"securesteps.tn","description":"Cybersecurity assessments, insights, and clear remediation.","url":"https:\/\/www.securesteps.tn\/ar\/"},{"@type":"Person","@id":"https:\/\/www.securesteps.tn\/ar\/author\/zied_belhotmail-com\/#author","url":"https:\/\/www.securesteps.tn\/ar\/author\/zied_belhotmail-com\/","name":"Zied BELGHITH","image":{"@type":"ImageObject","@id":"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/96c18e9fc52e08c45006f84f0408ced54b58a24c6b0f5677185df3b75650034d?s=96&d=mm&r=g","width":96,"height":96,"caption":"Zied BELGHITH"}},{"@type":"WebPage","@id":"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/#webpage","url":"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/","name":"perchance \u2014 Browser Extension Origin and Context Confusion | NNS CTF - Secure Steps","description":"Detailed NNS CTF browser-extension walkthrough covering URL validation, postMessage origin confusion, sanitizer replacement, trusted-origin execution, and defenses.","inLanguage":"ar","isPartOf":{"@id":"https:\/\/www.securesteps.tn\/ar\/#website"},"breadcrumb":{"@id":"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/#breadcrumblist"},"author":{"@id":"https:\/\/www.securesteps.tn\/ar\/author\/zied_belhotmail-com\/#author"},"creator":{"@id":"https:\/\/www.securesteps.tn\/ar\/author\/zied_belhotmail-com\/#author"},"datePublished":"2026-09-06T16:38:56+00:00","dateModified":"2026-09-06T16:38:56+00:00"},{"@type":"WebSite","@id":"https:\/\/www.securesteps.tn\/ar\/#website","url":"https:\/\/www.securesteps.tn\/ar\/","name":"Secure Steps","description":"Cybersecurity assessments, insights, and clear remediation.","inLanguage":"ar","publisher":{"@id":"https:\/\/www.securesteps.tn\/ar\/#organization"}}]},"og:locale":"ar_AR","og:site_name":"Secure Steps - Cybersecurity assessments, insights, and clear remediation.","og:type":"article","og:title":"perchance \u2014 Browser Extension Origin and Context Confusion | NNS CTF - Secure Steps","og:description":"Detailed NNS CTF browser-extension walkthrough covering URL validation, postMessage origin confusion, sanitizer replacement, trusted-origin execution, and defenses.","og:url":"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/","article:published_time":"2026-09-06T16:38:56+00:00","article:modified_time":"2026-09-06T16:38:56+00:00","twitter:card":"summary","twitter:title":"perchance \u2014 Browser Extension Origin and Context Confusion | NNS CTF - Secure Steps","twitter:description":"Detailed NNS CTF browser-extension walkthrough covering URL validation, postMessage origin confusion, sanitizer replacement, trusted-origin execution, and defenses."},"aioseo_meta_data":{"post_id":"1444","title":null,"description":null,"keywords":null,"keyphrases":{"focus":[],"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2026-09-06 16:29:40","updated":"2026-09-07 05:50:49","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.securesteps.tn\/ar\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.securesteps.tn\/ar\/category\/webapplicationsecurity\/\" title=\"Web Application Security\">Web Application Security<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tperchance \u2014 Browser Extension Origin and Context Confusion | NNS CTF\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.securesteps.tn\/ar"},{"label":"Web Application Security","link":"https:\/\/www.securesteps.tn\/ar\/category\/webapplicationsecurity\/"},{"label":"perchance \u2014 Browser Extension Origin and Context Confusion | NNS CTF","link":"https:\/\/www.securesteps.tn\/ar\/perchance-nns-ctf-walkthrough\/"}],"_links":{"self":[{"href":"https:\/\/www.securesteps.tn\/ar\/wp-json\/wp\/v2\/posts\/1444","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securesteps.tn\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securesteps.tn\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securesteps.tn\/ar\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securesteps.tn\/ar\/wp-json\/wp\/v2\/comments?post=1444"}],"version-history":[{"count":1,"href":"https:\/\/www.securesteps.tn\/ar\/wp-json\/wp\/v2\/posts\/1444\/revisions"}],"predecessor-version":[{"id":1445,"href":"https:\/\/www.securesteps.tn\/ar\/wp-json\/wp\/v2\/posts\/1444\/revisions\/1445"}],"wp:attachment":[{"href":"https:\/\/www.securesteps.tn\/ar\/wp-json\/wp\/v2\/media?parent=1444"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securesteps.tn\/ar\/wp-json\/wp\/v2\/categories?post=1444"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securesteps.tn\/ar\/wp-json\/wp\/v2\/tags?post=1444"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}