Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…ocket ensure_app_websocket and setup_app take the AllowedOrigins the app interface accepts instead of attaching with Any, and main_window_builder's legacy path passes the window's predicted origin. Asking again for a cached interface with different origins fails with AppInterfaceOriginsMismatch instead of returning a port that refuses the handshake.
f492d78 to
c66a1d2
Compare
14bf71d to
178cebc
Compare
|
✔️ 178cebc - Conventional commits check succeeded. |
mattyg
left a comment
There was a problem hiding this comment.
Is this legacy approach something we should just be deprecating or removing? Do we have apps depending on it currently?
|
Nothing uses this path any more (kando, emergence and the example app all use IPC), so rather than predict origins we're removing it: see #21. Closing in favour of that. |
The legacy path attached an app interface with AllowedOrigins::Any and injected a reusable, non-expiring token into the page. No consumer uses it, so remove it rather than harden it (supersedes #19). BREAKING CHANGE: WindowOptions::use_app_websocket, the injected __HC_LAUNCHER_ENV__, Runtime::ensure_app_websocket, Runtime::setup_app and AppAuth are removed. Use Runtime::install_app_if_missing instead of setup_app.
The legacy path attached an app interface with AllowedOrigins::Any and injected a reusable, non-expiring token into the page. No consumer uses it, so remove it rather than harden it (supersedes #19). BREAKING CHANGE: WindowOptions::use_app_websocket, the injected __HC_LAUNCHER_ENV__, Runtime::ensure_app_websocket, Runtime::setup_app and AppAuth are removed. Use Runtime::install_app_if_missing instead of setup_app.
The legacy path attached an app interface with AllowedOrigins::Any and injected a reusable, non-expiring token into the page. No consumer uses it, so remove it rather than harden it (supersedes #19). BREAKING CHANGE: WindowOptions::use_app_websocket, the injected __HC_LAUNCHER_ENV__, Runtime::ensure_app_websocket, Runtime::setup_app and AppAuth are removed. Use Runtime::install_app_if_missing instead of setup_app.
The legacy path attached an app interface with AllowedOrigins::Any and injected a reusable, non-expiring token into the page. No consumer uses it, so remove it rather than harden it (supersedes #19). BREAKING CHANGE: WindowOptions::use_app_websocket, the injected __HC_LAUNCHER_ENV__, Runtime::ensure_app_websocket, Runtime::setup_app and AppAuth are removed. Use Runtime::install_app_if_missing instead of setup_app.
Summary
Stacked on #17. Review only the top commit. Rebase onto main once that PR merges.
The legacy app websocket attached its interface with
AllowedOrigins::Any, so any local page could connect with the injected token.Runtime::ensure_app_websocketandsetup_appnow take theAllowedOriginsthe interface accepts, andmain_window_builder's legacy path passes the window's own origin.That origin has to be predicted from the app config, because the interface is attached before the page exists.
origin::app_originmirrors how Tauri 2.11 resolves the URL. It assumes the defaultuse_https_scheme(off). An app that turns that on gets a refused handshake on Windows and Android.The token stays reusable and non-expiring on purpose. It is injected on every page load, and
@holochain/clientre-authenticates with it on reconnect.Asking again for a cached interface with different origins fails with
AppInterfaceOriginsMismatch, instead of returning a port that refuses the handshake.AppAuthrecords the origins.Breaking for
holochain-conductor-runtimecallers:ensure_app_websocketandsetup_apptake a newAllowedOriginsargument.AllowedOriginsis re-exported from both crates.TODO:
npm run cipasses