fix(runtime)!: remove the legacy app websocket - #21
Conversation
The legacy path attached an app interface with AllowedOrigins::Any and injected a reusable, non-expiring token into the page. No consumer uses it, so remove it rather than harden it (supersedes #19). BREAKING CHANGE: WindowOptions::use_app_websocket, the injected __HC_LAUNCHER_ENV__, Runtime::ensure_app_websocket, Runtime::setup_app and AppAuth are removed. Use Runtime::install_app_if_missing instead of setup_app.
|
✔️ b9353a9 - Conventional commits check succeeded. |
1 similar comment
|
✔️ b9353a9 - Conventional commits check succeeded. |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Stacked on #17. Review only the top commit. Rebase onto main once that PR merges. Supersedes #19.
The legacy path attached an app interface with
AllowedOrigins::Anyand injected a reusable, non-expiring token into the page, so any local page could connect with it. #19 restricted the interface to the window's origin, but that origin has to be predicted from the app config, and the prediction fails on Windows and Android whenuse_https_schemeis on. No consumer uses the path (kando, emergence and the example app all use Tauri IPC), so this removes it instead.Removed:
WindowOptions::use_app_websocketand theinjectHolochainClientEnv/__HC_LAUNCHER_ENV__injection.main_window_builderalways wires the window over IPC.Runtime::ensure_app_websocket,Runtime::setup_app,AppAuthand the private helpers that issued the token and attached the interface.setup_app's tests now coverinstall_app_if_missing, which does the same thing without the websocket.Breaking for consumers: drop
use_app_websocketfromWindowOptions, and callinstall_app_if_missingwhere you calledsetup_app.dist-jsis rebuilt. The build script fails as-is under TypeScript 7 (TS5112 from the dependabot bump; separate fix), so I built it with--ignoreConfig. The bundle also picks up the newer@tauri-apps/apiand native class fields. A new test asserts the bundle no longer contains__HC_LAUNCHER_ENV__.TODO:
npm run cipasses (rancargo fmt --check,cargo clippy --workspace --all-targets -D warningsand the runtime and plugin test suites locally)AI Policy discosure: Generated under my direction by LLM