Skip to content

fix(runtime)!: accept only the window's origin on the legacy app websocket - #19

Closed
zippy wants to merge 1 commit into
security/navigation-lockfrom
security/app-websocket-origins
Closed

zippy wants to merge 1 commit into
security/navigation-lockfrom
security/app-websocket-origins

Conversation

@zippy

@zippy zippy commented Sep 24, 2026

Copy link
Copy Markdown
Member

Summary

Stacked on #17. Review only the top commit. Rebase onto main once that PR merges.

The legacy app websocket attached its interface with AllowedOrigins::Any, so any local page could connect with the injected token. Runtime::ensure_app_websocket and setup_app now take the AllowedOrigins the interface accepts, and main_window_builder's legacy path passes the window's own origin.

That origin has to be predicted from the app config, because the interface is attached before the page exists. origin::app_origin mirrors how Tauri 2.11 resolves the URL. It assumes the default use_https_scheme (off). An app that turns that on gets a refused handshake on Windows and Android.

The token stays reusable and non-expiring on purpose. It is injected on every page load, and @holochain/client re-authenticates with it on reconnect.

Asking again for a cached interface with different origins fails with AppInterfaceOriginsMismatch, instead of returning a port that refuses the handshake. AppAuth records the origins.

Breaking for holochain-conductor-runtime callers: ensure_app_websocket and setup_app take a new AllowedOrigins argument. AllowedOrigins is re-exported from both crates.

TODO:

  • CHANGELOG updated with appropriate info
  • npm run ci passes

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 6ee27c21-64dd-44c8-835e-73c00466dc2e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

…ocket

ensure_app_websocket and setup_app take the AllowedOrigins the app interface
accepts instead of attaching with Any, and main_window_builder's legacy path
passes the window's predicted origin. Asking again for a cached interface with
different origins fails with AppInterfaceOriginsMismatch instead of returning a
port that refuses the handshake.
@zippy
zippy force-pushed the security/navigation-lock branch from f492d78 to c66a1d2 Compare September 24, 2026 18:13
@zippy
zippy force-pushed the security/app-websocket-origins branch from 14bf71d to 178cebc Compare September 24, 2026 18:13
@cocogitto-bot

cocogitto-bot Bot commented Sep 24, 2026

Copy link
Copy Markdown

✔️ 178cebc - Conventional commits check succeeded.

@zippy
zippy marked this pull request as ready for review September 25, 2026 14:39
@zippy
zippy requested a review from mattyg September 25, 2026 14:39
@mattyg
mattyg requested a review from a team September 28, 2026 20:01

@mattyg mattyg left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this legacy approach something we should just be deprecating or removing? Do we have apps depending on it currently?

@zippy zippy mentioned this pull request Sep 29, 2026
1 of 2 tasks
@zippy

zippy commented Sep 29, 2026

Copy link
Copy Markdown
Member Author

Nothing uses this path any more (kando, emergence and the example app all use IPC), so rather than predict origins we're removing it: see #21. Closing in favour of that.

@zippy zippy closed this Sep 29, 2026
zippy added a commit that referenced this pull request Sep 29, 2026
The legacy path attached an app interface with AllowedOrigins::Any and
injected a reusable, non-expiring token into the page. No consumer uses it,
so remove it rather than harden it (supersedes #19).

BREAKING CHANGE: WindowOptions::use_app_websocket, the injected
__HC_LAUNCHER_ENV__, Runtime::ensure_app_websocket, Runtime::setup_app and
AppAuth are removed. Use Runtime::install_app_if_missing instead of setup_app.
zippy added a commit that referenced this pull request Sep 30, 2026
The legacy path attached an app interface with AllowedOrigins::Any and
injected a reusable, non-expiring token into the page. No consumer uses it,
so remove it rather than harden it (supersedes #19).

BREAKING CHANGE: WindowOptions::use_app_websocket, the injected
__HC_LAUNCHER_ENV__, Runtime::ensure_app_websocket, Runtime::setup_app and
AppAuth are removed. Use Runtime::install_app_if_missing instead of setup_app.
zippy added a commit that referenced this pull request Sep 30, 2026
The legacy path attached an app interface with AllowedOrigins::Any and
injected a reusable, non-expiring token into the page. No consumer uses it,
so remove it rather than harden it (supersedes #19).

BREAKING CHANGE: WindowOptions::use_app_websocket, the injected
__HC_LAUNCHER_ENV__, Runtime::ensure_app_websocket, Runtime::setup_app and
AppAuth are removed. Use Runtime::install_app_if_missing instead of setup_app.
zippy added a commit that referenced this pull request Sep 30, 2026
The legacy path attached an app interface with AllowedOrigins::Any and
injected a reusable, non-expiring token into the page. No consumer uses it,
so remove it rather than harden it (supersedes #19).

BREAKING CHANGE: WindowOptions::use_app_websocket, the injected
__HC_LAUNCHER_ENV__, Runtime::ensure_app_websocket, Runtime::setup_app and
AppAuth are removed. Use Runtime::install_app_if_missing instead of setup_app.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants