Compare commits

...
Author SHA1 Message Date
Lotus CIandClaude Opus 5.5 5c3ac68328 feat: call page on its own origin, http://127.0.0.1:44548 (cinny #43)
The bundled Element Call page ran on the app's own origin
(http://localhost:44548), so the call frame could read the app's storage
(login token) and DOM. Serve it from http://127.0.0.1:44548 instead: the
same local server and bundle, a different origin.

- The local server binds 127.0.0.1 explicitly. The app is still loaded as
  http://localhost:44548 (its storage stays where it is; the engines try
  127.0.0.1 for `localhost`). Binding the name `localhost` could pick ::1
  only (Windows lists it first), and then 127.0.0.1 wouldn't answer.
- config.json: desktopCallOrigin = http://127.0.0.1:44548. cinny loads the
  call page from there only when this is set (cinny #43 PR).
- CSP frame-src allows http://127.0.0.1:44548.
- Permissions (on top of #22): the call page's origin gets microphone/
  camera/screen only; nothing else.
- The call page gets no IPC: the capability only matches
  http://localhost:44548.

Tested (Linux release build): the server listens on 127.0.0.1:44548 and
the app loads as http://localhost:44548; the call page loads from
127.0.0.1 inside the app under its CSP; from that frame parent.localStorage
and parent.document are SecurityError, while a same-origin frame (the old
setup) reads the app's storage. The call itself was tested in a simulated
desktop (Chromium, the WebView2 engine) against a local Synapse + LiveKit;
see the cinny PR. Rust tests 17 passed; Windows code type-checked.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
2026-09-29 00:09:41 -04:00
Lotus CIandClaude Opus 5.5 3e136d3729 fix: WebView permissions only for the app's own origin (#22)
Linux (WebKitGTK) allowed every permission request of every kind; Windows
(WebView2) auto-allowed mic/camera/notifications without checking who asked.

Now (src-tauri/src/webview_permissions.rs, unit-tested):
- Linux: microphone/camera/screen, device labels, notifications and location
  are granted when the page in the window is the app
  (http://localhost:44548; debug builds also the bundled/dev page).
  Everything else is denied (WebKitGTK has no prompt of its own). WebKitGTK
  doesn't say which frame asked; frames are gated earlier by the Permissions
  Policy (cinny gives microphone/camera only to the same-origin call frame).
- Windows: the same grants (minus location, which keeps WebView2's prompt),
  checked against the origin of the frame that asked (args.Uri()). Other
  origins are denied mic/camera/notifications/location; other kinds keep
  WebView2's default handling.
- Denials are logged ("webview: denied …").

Tested on Linux with a release build under Xvfb + PulseAudio (no WebDriver:
WebKit's automation mode bypasses the handler), before/after:
- app page: mic, device labels, location allowed (unchanged)
- same-origin call frame: mic allowed (unchanged)
- cross-origin frame without allow=: blocked before the handler (unchanged)
- foreign top-level page: mic, device labels, location now denied (were
  allowed)
Real cinny build: boots, logs in, no denials. Windows code type-checked
(x86_64-pc-windows-gnu).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
2026-09-28 20:03:11 -04:00
Lotus CI 11e102f7da chore: bump cinny submodule to be8e49a2
Build Lotus Chat Desktop / prepare (push) Successful in 5s
Build Lotus Chat Desktop / build-linux (push) Successful in 25m9s
Build Lotus Chat Desktop / build-arch (push) Successful in 12s
Build Lotus Chat Desktop / build-windows (push) Successful in 26m53s
Build Lotus Chat Desktop / update-manifest (push) Successful in 3s
2026-09-28 03:30:38 +00:00
jared 8ee90444ee Merge pull request #24: NVIDIA + Wayland keeps the GPU renderer
Build Lotus Chat Desktop / prepare (push) Successful in 5s
Build Lotus Chat Desktop / build-linux (push) Successful in 23m39s
Build Lotus Chat Desktop / build-arch (push) Successful in 13s
Build Lotus Chat Desktop / build-windows (push) Successful in 25m24s
Build Lotus Chat Desktop / update-manifest (push) Successful in 2s
2026-09-27 22:26:51 -04:00
Lotus CIandClaude Opus 5.5 bb5364b53c fix(linux): NVIDIA + Wayland keeps the GPU renderer (explicit-sync fix)
The 4.12.343 workaround (WEBKIT_DISABLE_DMABUF_RENDERER=1 + GDK_BACKEND=x11)
made the app launch but pushed every frame through shared memory under
XWayland: noticeably laggy at 3840x2058. The reporter's WAYLAND_DEBUG trace
showed the real cause on native Wayland:

  wl_display#1.error(wp_linux_drm_syncobj_surface_v1#51, 4,
    "explicit sync is used, but no acquire point is set")
  Gdk-Message: Error 71 (Protocol error) dispatching to Wayland display.

An explicit-sync bug, not a GBM format/modifier one. Their test matrix
(RTX 3070, driver 615.71.09, webkit2gtk 2.52.6, KDE Wayland):
- __NV_DISABLE_EXPLICIT_SYNC=1 alone: clean, GPU (DMA-BUF) renderer, smooth;
- WEBKIT_DISABLE_DMABUF_RENDERER=1 alone on Wayland: clean (no X11 needed);
- WEBKIT_DMABUF_RENDERER_DISABLE_GBM=1: same explicit-sync error on Wayland,
  "Failed to import DMABuf" under XWayland;
- X11/XWayland with the DMA-BUF renderer: "Failed to create GBM buffer".

New defaults when the NVIDIA driver is loaded:
- native Wayland: __NV_DISABLE_EXPLICIT_SYNC=1, GPU renderer kept;
- X11 session or user-forced GDK_BACKEND=x11: WEBKIT_DISABLE_DMABUF_RENDERER=1;
- never force X11 any more;
- LOTUS_GPU_SAFE_MODE=1: opt-in shared-memory rendering on Wayland too;
- LOTUS_NO_GPU_WORKAROUNDS=1 / user-set values: untouched.
One stderr line says what was set. 9 unit tests.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
2026-09-27 22:22:00 -04:00
jared 5b4528e4e5 Merge pull request #23: launch on NVIDIA + Wayland; webAppUrl
Build Lotus Chat Desktop / prepare (push) Successful in 2s
Build Lotus Chat Desktop / build-windows (push) Successful in 31m44s
Build Lotus Chat Desktop / build-linux (push) Successful in 27m16s
Build Lotus Chat Desktop / build-arch (push) Successful in 13s
Build Lotus Chat Desktop / update-manifest (push) Successful in 3s
2026-09-27 17:10:51 -04:00
6 changed files with 492 additions and 92 deletions
+1 -1
Submodule cinny updated: e2b23397bd...be8e49a2bb
+2 -1
View File
@@ -24,5 +24,6 @@
"basename": "/"
},
"gifApiKey": "",
"webAppUrl": "https://chat.lotusguild.org"
"webAppUrl": "https://chat.lotusguild.org",
"desktopCallOrigin": "http://127.0.0.1:44548"
}
+99 -49
View File
@@ -1,17 +1,22 @@
//! WebKitGTK workarounds for NVIDIA's proprietary driver on Linux.
//!
//! On NVIDIA + Wayland (reported on CachyOS/KDE, driver 615, webkit2gtk 2.52)
//! the app never shows a window: GDK dies with "Error 71 (Protocol error)
//! dispatching to Wayland display", and under XWayland WebKit's DMA-BUF
//! renderer then fails with "Failed to create GBM buffer … Invalid argument".
//! `WEBKIT_DISABLE_DMABUF_RENDERER=1 GDK_BACKEND=x11` makes it run normally.
//! Diagnosed on CachyOS/KDE Wayland, RTX 3070, driver 615.71.09, webkit2gtk
//! 2.52.6 (reported 2026-09-27, WAYLAND_DEBUG trace in the PR):
//! - Native Wayland: the compositor kills the connection with
//! `wp_linux_drm_syncobj_surface_v1 … "explicit sync is used, but no acquire
//! point is set"` (GDK: "Error 71 (Protocol error)"), i.e. an explicit-sync
//! bug between WebKit and the driver, not a buffer-format problem.
//! `__NV_DISABLE_EXPLICIT_SYNC=1` fixes it and keeps WebKit's GPU (DMA-BUF)
//! renderer, so that is the default on native Wayland.
//! - X11 / XWayland: the DMA-BUF renderer can't allocate or import buffers
//! ("Failed to create GBM buffer … Invalid argument", "Failed to import
//! DMABuf"), so there it is disabled (`WEBKIT_DISABLE_DMABUF_RENDERER=1`,
//! shared-memory frames). We never force X11 any more.
//!
//! So, before GTK/WebKit initialise, and only when the NVIDIA driver is loaded:
//! - `WEBKIT_DISABLE_DMABUF_RENDERER=1`;
//! - on a Wayland session with XWayland available, `GDK_BACKEND=x11`.
//!
//! Anything the user already set wins, and `LOTUS_NO_GPU_WORKAROUNDS=1`
//! disables all of it (e.g. once a newer driver/WebKit fixes this).
//! Opt-ins / opt-outs (anything the user already set always wins):
//! - `LOTUS_GPU_SAFE_MODE=1`: last resort, shared-memory rendering on Wayland
//! too (slower, especially at high resolutions).
//! - `LOTUS_NO_GPU_WORKAROUNDS=1`: change nothing.
/// Environment variables to set: pure, for tests.
pub(crate) fn decide(
@@ -22,15 +27,30 @@ pub(crate) fn decide(
if !nvidia || set("LOTUS_NO_GPU_WORKAROUNDS") {
return Vec::new();
}
let mut out = Vec::new();
if !set("WEBKIT_DISABLE_DMABUF_RENDERER") {
out.push(("WEBKIT_DISABLE_DMABUF_RENDERER", "1"));
}
let wayland = set("WAYLAND_DISPLAY")
let wayland_session = set("WAYLAND_DISPLAY")
|| get("XDG_SESSION_TYPE").is_some_and(|v| v.eq_ignore_ascii_case("wayland"));
// Only fall back to X11 when there is an X server (XWayland) to talk to.
if wayland && set("DISPLAY") && !set("GDK_BACKEND") {
out.push(("GDK_BACKEND", "x11"));
// GTK uses Wayland unless GDK_BACKEND says otherwise (it may list
// several, e.g. "wayland,x11": the first one wins).
let native_wayland = wayland_session
&& get("GDK_BACKEND").map_or(true, |v| {
v.is_empty()
|| v.trim_start().to_ascii_lowercase().starts_with("wayland")
|| v.trim() == "*"
});
let mut out = Vec::new();
let mut want = |k: &'static str, v: &'static str| {
if !set(k) {
out.push((k, v));
}
};
if native_wayland {
want("__NV_DISABLE_EXPLICIT_SYNC", "1");
if set("LOTUS_GPU_SAFE_MODE") {
want("WEBKIT_DISABLE_DMABUF_RENDERER", "1");
}
} else {
want("WEBKIT_DISABLE_DMABUF_RENDERER", "1");
}
out
}
@@ -44,9 +64,20 @@ fn nvidia_driver_loaded() -> bool {
/// Call first thing in `main`, before anything starts GTK or spawns threads.
pub fn apply() {
#[cfg(target_os = "linux")]
for (key, value) in decide(nvidia_driver_loaded(), |k| std::env::var(k).ok()) {
eprintln!("gpu-workarounds: NVIDIA driver detected, setting {key}={value} (LOTUS_NO_GPU_WORKAROUNDS=1 to disable)");
std::env::set_var(key, value);
{
let changes = decide(nvidia_driver_loaded(), |k| std::env::var(k).ok());
if changes.is_empty() {
return;
}
let list: Vec<String> = changes.iter().map(|(k, v)| format!("{k}={v}")).collect();
eprintln!(
"gpu-workarounds: NVIDIA driver detected, setting {} \
(LOTUS_GPU_SAFE_MODE=1 for shared-memory rendering, LOTUS_NO_GPU_WORKAROUNDS=1 to disable)",
list.join(" ")
);
for (key, value) in changes {
std::env::set_var(key, value);
}
}
}
@@ -71,51 +102,70 @@ mod tests {
}
#[test]
fn nvidia_wayland_gets_both() {
fn nvidia_wayland_keeps_gpu_renderer_and_disables_explicit_sync() {
assert_eq!(
run(true, WAYLAND),
vec![
("WEBKIT_DISABLE_DMABUF_RENDERER", "1"),
("GDK_BACKEND", "x11")
]
vec![("__NV_DISABLE_EXPLICIT_SYNC", "1")]
);
}
#[test]
fn nvidia_x11_session_only_disables_dmabuf() {
assert_eq!(
run(true, &[("DISPLAY", ":0")]),
vec![("WEBKIT_DISABLE_DMABUF_RENDERER", "1")]
);
}
#[test]
fn wayland_without_xwayland_keeps_wayland() {
assert_eq!(
run(true, &[("WAYLAND_DISPLAY", "wayland-0")]),
vec![("WEBKIT_DISABLE_DMABUF_RENDERER", "1")]
);
fn never_forces_x11() {
for env in [
WAYLAND,
&[("DISPLAY", ":0")][..],
&[("WAYLAND_DISPLAY", "w")][..],
] {
assert!(run(true, env).iter().all(|(k, _)| *k != "GDK_BACKEND"));
}
}
#[test]
fn xdg_session_type_counts_as_wayland() {
assert_eq!(
run(true, &[("XDG_SESSION_TYPE", "wayland"), ("DISPLAY", ":1")]),
run(true, &[("XDG_SESSION_TYPE", "wayland")]),
vec![("__NV_DISABLE_EXPLICIT_SYNC", "1")]
);
}
#[test]
fn nvidia_x11_session_disables_dmabuf_renderer() {
assert_eq!(
run(true, &[("DISPLAY", ":0"), ("XDG_SESSION_TYPE", "x11")]),
vec![("WEBKIT_DISABLE_DMABUF_RENDERER", "1")]
);
}
#[test]
fn user_forced_x11_on_wayland_counts_as_x11() {
let mut env = WAYLAND.to_vec();
env.push(("GDK_BACKEND", "x11"));
assert_eq!(
run(true, &env),
vec![("WEBKIT_DISABLE_DMABUF_RENDERER", "1")]
);
let mut env = WAYLAND.to_vec();
env.push(("GDK_BACKEND", "wayland,x11"));
assert_eq!(run(true, &env), vec![("__NV_DISABLE_EXPLICIT_SYNC", "1")]);
}
#[test]
fn safe_mode_adds_shared_memory_rendering_on_wayland() {
let mut env = WAYLAND.to_vec();
env.push(("LOTUS_GPU_SAFE_MODE", "1"));
assert_eq!(
run(true, &env),
vec![
("WEBKIT_DISABLE_DMABUF_RENDERER", "1"),
("GDK_BACKEND", "x11")
("__NV_DISABLE_EXPLICIT_SYNC", "1"),
("WEBKIT_DISABLE_DMABUF_RENDERER", "1")
]
);
}
#[test]
fn user_settings_win() {
let env = [
("WAYLAND_DISPLAY", "wayland-0"),
("DISPLAY", ":0"),
("WEBKIT_DISABLE_DMABUF_RENDERER", "0"),
("GDK_BACKEND", "wayland"),
];
let mut env = WAYLAND.to_vec();
env.push(("__NV_DISABLE_EXPLICIT_SYNC", "0"));
assert!(run(true, &env).is_empty());
}
+116 -40
View File
@@ -13,6 +13,8 @@ use tauri_plugin_opener::OpenerExt;
pub mod gpu_workarounds;
mod native;
#[cfg(any(target_os = "linux", target_os = "windows", test))]
mod webview_permissions;
/// Bring the main window to the foreground from the tray / a hidden /
/// minimized state. Shared by the tray, single-instance, and deep-link paths.
@@ -953,7 +955,17 @@ pub fn run() {
native::hotkeys::global_hotkeys_supported,
native::hotkeys::set_global_hotkeys,
])
.plugin(tauri_plugin_localhost::Builder::new(port).build())
// Bound to 127.0.0.1 explicitly (cinny #43). The app is still loaded as
// http://localhost:{port} (its storage lives under that origin, and the
// engines try 127.0.0.1 for `localhost`); the bundled call page is
// loaded as http://127.0.0.1:{port}, a separate origin on the same
// server. Binding the name `localhost` could pick ::1 only (Windows
// lists it first), and then the call page wouldn't load.
.plugin(
tauri_plugin_localhost::Builder::new(port)
.host("127.0.0.1")
.build(),
)
.plugin(
// DECORATIONS is excluded: the custom-chrome toggle (set_custom_chrome)
// owns the decorated flag. Letting window-state restore a saved
@@ -1221,41 +1233,76 @@ pub fn run() {
let _ = window_vibrancy::apply_mica(&window, Some(true));
}
// Auto-grant camera, microphone, and notification permissions in WebView2.
#[cfg(target_os = "windows")]
window.with_webview(|webview| {
use webview2_com::{
Microsoft::Web::WebView2::Win32::{
COREWEBVIEW2_PERMISSION_KIND,
COREWEBVIEW2_PERMISSION_KIND_CAMERA,
COREWEBVIEW2_PERMISSION_KIND_MICROPHONE,
COREWEBVIEW2_PERMISSION_KIND_NOTIFICATIONS,
COREWEBVIEW2_PERMISSION_STATE_ALLOW,
},
PermissionRequestedEventHandler,
};
// cinny-desktop #22: the app's own page gets the microphone, camera
// and notifications without a prompt; other origins (room widgets,
// link-preview embeds) are refused them. See webview_permissions.
#[cfg(any(target_os = "linux", target_os = "windows"))]
let app_origins = webview_permissions::AppOrigins::new(
port,
app.config().build.dev_url.as_ref(),
);
let controller = webview.controller();
if let Ok(core) = unsafe { controller.CoreWebView2() } {
let handler = PermissionRequestedEventHandler::create(Box::new(
|_sender, args| {
if let Some(args) = args {
let mut kind = COREWEBVIEW2_PERMISSION_KIND(0);
unsafe { args.PermissionKind(&mut kind) }?;
if kind == COREWEBVIEW2_PERMISSION_KIND_MICROPHONE
|| kind == COREWEBVIEW2_PERMISSION_KIND_CAMERA
|| kind == COREWEBVIEW2_PERMISSION_KIND_NOTIFICATIONS
{
unsafe {
args.SetState(COREWEBVIEW2_PERMISSION_STATE_ALLOW)
}?;
}
}
Ok(())
#[cfg(target_os = "windows")]
window.with_webview({
let app_origins = app_origins.clone();
move |webview| {
use webview2_com::{
Microsoft::Web::WebView2::Win32::{
COREWEBVIEW2_PERMISSION_KIND,
COREWEBVIEW2_PERMISSION_KIND_CAMERA,
COREWEBVIEW2_PERMISSION_KIND_GEOLOCATION,
COREWEBVIEW2_PERMISSION_KIND_MICROPHONE,
COREWEBVIEW2_PERMISSION_KIND_NOTIFICATIONS,
COREWEBVIEW2_PERMISSION_STATE_ALLOW,
COREWEBVIEW2_PERMISSION_STATE_DENY,
},
));
let mut token = Default::default();
let _ = unsafe { core.add_PermissionRequested(&handler, &mut token) };
PermissionRequestedEventHandler,
};
use webview_permissions::{decide, Decision, Kind, WINDOWS_GRANTS};
let controller = webview.controller();
if let Ok(core) = unsafe { controller.CoreWebView2() } {
let handler = PermissionRequestedEventHandler::create(Box::new(
move |_sender, args| {
if let Some(args) = args {
let mut raw = COREWEBVIEW2_PERMISSION_KIND(0);
unsafe { args.PermissionKind(&mut raw) }?;
let kind = if raw == COREWEBVIEW2_PERMISSION_KIND_MICROPHONE
|| raw == COREWEBVIEW2_PERMISSION_KIND_CAMERA
{
Kind::Media
} else if raw == COREWEBVIEW2_PERMISSION_KIND_NOTIFICATIONS {
Kind::Notifications
} else if raw == COREWEBVIEW2_PERMISSION_KIND_GEOLOCATION {
Kind::Geolocation
} else {
Kind::Other
};
// The origin of the frame that asked.
let mut uri = windows::core::PWSTR::null();
unsafe { args.Uri(&mut uri) }?;
let uri = webview2_com::take_pwstr(uri);
match decide(kind, &uri, &app_origins, WINDOWS_GRANTS) {
Decision::Allow => unsafe {
args.SetState(COREWEBVIEW2_PERMISSION_STATE_ALLOW)
}?,
Decision::Deny => {
eprintln!(
"webview: denied {kind:?} permission to {uri}"
);
unsafe {
args.SetState(COREWEBVIEW2_PERMISSION_STATE_DENY)
}?
}
Decision::Default => {}
}
}
Ok(())
},
));
let mut token = Default::default();
let _ = unsafe { core.add_PermissionRequested(&handler, &mut token) };
}
}
})?;
@@ -1263,19 +1310,48 @@ pub fn run() {
// default (unlike WebView2/WKWebView), which leaves
// `navigator.mediaDevices` undefined and makes Element Call
// report "browser does not support WebRTC". Turn them on and
// auto-grant the resulting camera/mic permission prompt, mirroring
// the WebView2 handling above.
// answer the permission requests, mirroring the WebView2 handling
// above. WebKitGTK doesn't say which frame asked, so the origin
// checked is the page in the window (see webview_permissions).
#[cfg(target_os = "linux")]
window.with_webview(|webview| {
use webkit2gtk::{PermissionRequestExt, SettingsExt, WebViewExt};
window.with_webview(move |webview| {
use webkit2gtk::glib::prelude::ObjectExt;
use webkit2gtk::{
DeviceInfoPermissionRequest, GeolocationPermissionRequest,
NotificationPermissionRequest, PermissionRequestExt, SettingsExt,
UserMediaPermissionRequest, WebViewExt,
};
use webview_permissions::{decide, Decision, Kind, LINUX_GRANTS};
let wv = webview.inner();
if let Some(settings) = WebViewExt::settings(&wv) {
settings.set_enable_media_stream(true);
settings.set_enable_webrtc(true);
}
wv.connect_permission_request(|_webview, request| {
request.allow();
wv.connect_permission_request(move |wv, request| {
let kind = if request.is::<UserMediaPermissionRequest>() {
Kind::Media
} else if request.is::<DeviceInfoPermissionRequest>() {
Kind::DeviceInfo
} else if request.is::<NotificationPermissionRequest>() {
Kind::Notifications
} else if request.is::<GeolocationPermissionRequest>() {
Kind::Geolocation
} else {
Kind::Other
};
let uri = wv.uri().map(|u| u.to_string()).unwrap_or_default();
match decide(kind, &uri, &app_origins, LINUX_GRANTS) {
Decision::Allow => request.allow(),
// No prompt of our own: anything not granted is denied.
Decision::Deny | Decision::Default => {
eprintln!(
"webview: denied {} to {uri}",
request.type_().name()
);
request.deny();
}
}
true
});
})?;
+273
View File
@@ -0,0 +1,273 @@
//! Which WebView permission requests the app grants (cinny-desktop #22).
//!
//! The web client asks for the microphone/camera/screen (calls, voice
//! messages), the device list (audio-output picker), notifications and the
//! location (location sharing). Those are granted without a prompt, but only
//! to the app's own origin. Everything else is left alone (Windows: WebView2's
//! own prompt) or denied (Linux: WebKitGTK has no prompt of its own).
//!
//! What "the requesting origin" means differs per engine:
//! - WebView2 reports the origin of the frame that asked (`args.Uri()`), so a
//! room widget or link-preview embed is refused here.
//! - WebKitGTK doesn't say which frame asked; the check is on the page loaded
//! in the window. Frames are gated before the request gets this far by the
//! Permissions Policy: cinny only puts `microphone; camera` in the `allow=`
//! of the call frame, and cross-origin frames get neither location nor
//! notifications.
//!
//! The call frame (cinny #43): the bundled Element Call page is loaded from
//! `http://127.0.0.1:{port}`, the same local server on a second origin, so it
//! can't reach the app's storage. WebView2 reports that origin for the call's
//! microphone/camera requests; it gets media and nothing else.
use tauri::Url;
/// A permission request, reduced to what the policy cares about.
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
pub(crate) enum Kind {
/// Microphone, camera or screen capture (getUserMedia/getDisplayMedia).
Media,
/// Device labels/ids from enumerateDevices (WebKitGTK only).
#[cfg_attr(not(target_os = "linux"), allow(dead_code))]
DeviceInfo,
Notifications,
Geolocation,
/// Anything else: clipboard read, storage access, pointer lock, DRM, …
Other,
}
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
pub(crate) enum Decision {
Allow,
Deny,
/// Let the engine decide (WebView2 prompts; WebKitGTK denies).
Default,
}
/// What the Linux (WebKitGTK) handler grants to the app.
#[cfg_attr(not(target_os = "linux"), allow(dead_code))]
pub(crate) const LINUX_GRANTS: &[Kind] = &[
Kind::Media,
Kind::DeviceInfo,
Kind::Notifications,
Kind::Geolocation,
];
/// What the Windows (WebView2) handler grants to the app. Location keeps
/// WebView2's own prompt, as before.
#[cfg_attr(not(target_os = "windows"), allow(dead_code))]
pub(crate) const WINDOWS_GRANTS: &[Kind] = &[Kind::Media, Kind::Notifications];
/// The decision for a request of `kind` from `uri`.
pub(crate) fn decide(kind: Kind, uri: &str, app: &AppOrigins, grants: &[Kind]) -> Decision {
if kind == Kind::Other {
return Decision::Default;
}
if app.is_call_frame(uri) {
// The call page: microphone/camera/screen only.
return if kind == Kind::Media && grants.contains(&kind) {
Decision::Allow
} else {
Decision::Deny
};
}
if !app.contains(uri) {
return Decision::Deny;
}
if grants.contains(&kind) {
Decision::Allow
} else {
Decision::Default
}
}
/// scheme, host, port (explicit or the scheme's default).
type Origin = (String, String, Option<u16>);
fn origin_of(uri: &str) -> Option<Origin> {
let url = Url::parse(uri).ok()?;
let host = url.host_str()?.to_ascii_lowercase();
Some((url.scheme().to_owned(), host, url.port_or_known_default()))
}
/// The origins the app's own page is served from, and the call page's.
#[derive(Clone, Debug)]
pub(crate) struct AppOrigins {
app: Vec<Origin>,
call: Option<Origin>,
}
impl AppOrigins {
/// Release builds load `http://localhost:{port}` (tauri-plugin-localhost).
/// Debug builds load the bundled page (`tauri://localhost`, or
/// `http://tauri.localhost` on Windows) or, under `tauri dev`, `dev_url`.
pub(crate) fn new(port: u16, dev_url: Option<&Url>) -> Self {
let mut uris = vec![format!("http://localhost:{port}/")];
if cfg!(debug_assertions) {
uris.push("tauri://localhost/".into());
uris.push("http://tauri.localhost/".into());
if let Some(dev) = dev_url {
uris.push(dev.to_string());
}
}
Self {
app: uris.iter().filter_map(|u| origin_of(u)).collect(),
call: origin_of(&format!("http://127.0.0.1:{port}/")),
}
}
/// The app's own page.
pub(crate) fn contains(&self, uri: &str) -> bool {
origin_of(uri).is_some_and(|o| self.app.contains(&o))
}
/// The call page on its own origin (`http://127.0.0.1:{port}`).
pub(crate) fn is_call_frame(&self, uri: &str) -> bool {
origin_of(uri).is_some_and(|o| self.call.as_ref() == Some(&o))
}
}
#[cfg(test)]
mod tests {
use super::*;
fn app() -> AppOrigins {
AppOrigins::new(44548, None)
}
#[test]
fn app_origin_matches_only_the_app() {
let app = app();
assert!(app.contains("http://localhost:44548/"));
assert!(app.contains("http://localhost:44548/#/home/!room:server"));
assert!(app.contains("http://LOCALHOST:44548/public/element-call/index.html"));
for other in [
"http://localhost:44549/",
"https://localhost:44548/",
"http://127.0.0.1:44548/",
"http://localhost/",
"http://localhost.evil.example:44548/",
"http://evil.example/?http://localhost:44548/",
"https://www.youtube-nocookie.com/embed/x",
"https://chat.lotusguild.org/",
"about:blank",
"data:text/html,hi",
"null",
"",
] {
assert!(!app.contains(other), "{other}");
}
}
#[test]
fn debug_builds_also_accept_the_bundled_and_dev_pages() {
let dev = Url::parse("http://localhost:8080").unwrap();
let app = AppOrigins::new(44548, Some(&dev));
assert_eq!(
app.contains("tauri://localhost/index.html"),
cfg!(debug_assertions)
);
assert_eq!(
app.contains("http://tauri.localhost/"),
cfg!(debug_assertions)
);
assert_eq!(
app.contains("http://localhost:8080/"),
cfg!(debug_assertions)
);
assert!(app.contains("http://localhost:44548/"));
assert!(!app.contains("tauri://evil/"));
}
#[test]
fn app_gets_its_grants_without_a_prompt() {
let app = app();
let uri = "http://localhost:44548/";
for kind in [
Kind::Media,
Kind::DeviceInfo,
Kind::Notifications,
Kind::Geolocation,
] {
assert_eq!(
decide(kind, uri, &app, LINUX_GRANTS),
Decision::Allow,
"{kind:?}"
);
}
assert_eq!(
decide(Kind::Media, uri, &app, WINDOWS_GRANTS),
Decision::Allow
);
assert_eq!(
decide(Kind::Notifications, uri, &app, WINDOWS_GRANTS),
Decision::Allow
);
// Location on Windows keeps WebView2's prompt.
assert_eq!(
decide(Kind::Geolocation, uri, &app, WINDOWS_GRANTS),
Decision::Default
);
}
#[test]
fn other_origins_are_refused() {
let app = app();
for uri in [
"https://widget.example/",
"https://www.youtube-nocookie.com/embed/x",
"",
] {
for kind in [
Kind::Media,
Kind::DeviceInfo,
Kind::Notifications,
Kind::Geolocation,
] {
assert_eq!(decide(kind, uri, &app, LINUX_GRANTS), Decision::Deny);
assert_eq!(decide(kind, uri, &app, WINDOWS_GRANTS), Decision::Deny);
}
}
}
#[test]
fn call_frame_gets_media_only() {
let app = app();
let call = "http://127.0.0.1:44548/public/element-call/index.html?widgetId=x";
assert!(app.is_call_frame(call));
assert!(!app.contains(call));
for grants in [LINUX_GRANTS, WINDOWS_GRANTS] {
assert_eq!(decide(Kind::Media, call, &app, grants), Decision::Allow);
for kind in [Kind::DeviceInfo, Kind::Notifications, Kind::Geolocation] {
assert_eq!(decide(kind, call, &app, grants), Decision::Deny, "{kind:?}");
}
assert_eq!(decide(Kind::Other, call, &app, grants), Decision::Default);
}
for not_call in [
"http://127.0.0.1:44549/",
"https://127.0.0.1:44548/",
"http://127.0.0.2:44548/",
"http://[::1]:44548/",
] {
assert!(!app.is_call_frame(not_call), "{not_call}");
assert_eq!(
decide(Kind::Media, not_call, &app, WINDOWS_GRANTS),
Decision::Deny
);
}
}
#[test]
fn other_kinds_are_left_to_the_engine() {
let app = app();
for uri in ["http://localhost:44548/", "https://widget.example/"] {
assert_eq!(
decide(Kind::Other, uri, &app, LINUX_GRANTS),
Decision::Default
);
assert_eq!(
decide(Kind::Other, uri, &app, WINDOWS_GRANTS),
Decision::Default
);
}
}
}
+1 -1
View File
@@ -71,7 +71,7 @@
},
"app": {
"security": {
"csp": "default-src 'self'; script-src 'self' 'unsafe-eval' 'sha256-dT6noyex1I8o5CS9Sx/y8UOqwpZYIridpGz92gcObIM='; style-src 'self' 'unsafe-inline'; font-src 'self' data:; img-src 'self' data: blob: http: https:; media-src 'self' blob: data: mediastream: http: https:; worker-src 'self' blob:; frame-src 'self' blob: https://www.openstreetmap.org https://www.youtube-nocookie.com https://www.youtube.com https://player.vimeo.com https://www.tiktok.com https://www.dailymotion.com https://geo.dailymotion.com https://streamable.com https://player.twitch.tv https://clips.twitch.tv https://open.spotify.com https://w.soundcloud.com https://embed.music.apple.com https://platform.twitter.com https://www.instagram.com https://embed.tidal.com https://www.redditmedia.com https://embed.reddit.com https://embed.bsky.app https://www.loom.com https://player.kick.com https://www.mixcloud.com https://widget.deezer.com https://store.steampowered.com; connect-src 'self' blob: data: ipc: ws: wss: http: https: http://ipc.localhost; object-src 'none'; base-uri 'self'"
"csp": "default-src 'self'; script-src 'self' 'unsafe-eval' 'sha256-dT6noyex1I8o5CS9Sx/y8UOqwpZYIridpGz92gcObIM='; style-src 'self' 'unsafe-inline'; font-src 'self' data:; img-src 'self' data: blob: http: https:; media-src 'self' blob: data: mediastream: http: https:; worker-src 'self' blob:; frame-src 'self' blob: http://127.0.0.1:44548 https://www.openstreetmap.org https://www.youtube-nocookie.com https://www.youtube.com https://player.vimeo.com https://www.tiktok.com https://www.dailymotion.com https://geo.dailymotion.com https://streamable.com https://player.twitch.tv https://clips.twitch.tv https://open.spotify.com https://w.soundcloud.com https://embed.music.apple.com https://platform.twitter.com https://www.instagram.com https://embed.tidal.com https://www.redditmedia.com https://embed.reddit.com https://embed.bsky.app https://www.loom.com https://player.kick.com https://www.mixcloud.com https://widget.deezer.com https://store.steampowered.com; connect-src 'self' blob: data: ipc: ws: wss: http: https: http://ipc.localhost; object-src 'none'; base-uri 'self'"
}
}
}