38 lines
1.5 KiB
TypeScript
38 lines
1.5 KiB
TypeScript
/**
|
|||
|
|
* [Gitea #43] Where the Element Call page is loaded from.
|
||
|
|
*
|
||
|
|
* By default it's the copy bundled with this app (same origin). With
|
||
|
|
* `elementCallUrl` in config.json (e.g.
|
||
|
|
* "https://call.chat.lotusguild.org/public/element-call/index.html") the web
|
||
|
|
* app loads it from that origin instead, so the call frame can no longer
|
||
|
|
* reach this origin's storage (login token, crypto store) or service worker.
|
||
|
|
*
|
||
|
|
* Web only: the desktop app keeps its bundled copy (its CSP doesn't allow
|
||
|
|
* another frame origin, and a network copy could drift from the bundle).
|
||
|
|
* Anything that isn't an absolute https URL (http only on localhost, for
|
||
|
|
* development) is ignored, so a bad value falls
|
||
|
|
* back to the bundled page instead of breaking calls.
|
||
|
|
*/
|
||
|
|
export const resolveCallPageUrl = (value: unknown, desktop: boolean): string | undefined => {
|
||
|
|
if (desktop || typeof value !== 'string' || value.trim() === '') return undefined;
|
||
|
|
try {
|
||
|
|
const url = new URL(value);
|
||
|
|
// http only for local development (localhost is a secure context).
|
||
|
|
const local = url.hostname === 'localhost' || url.hostname === '127.0.0.1';
|
||
|
|
if (url.protocol !== 'https:' && !(url.protocol === 'http:' && local)) return undefined;
|
||
|
|
url.search = '';
|
||
|
|
url.hash = '';
|
||
|
|
return url.href;
|
||
|
|
} catch {
|
||
|
|
return undefined;
|
||
|
|
}
|
||
|
|
};
|
||
|
|
|
||
|
|
let callPageUrl: string | undefined;
|
||
|
|
|
||
|
|
export const setCallPageUrl = (url: string | undefined): void => {
|
||
|
|
callPageUrl = url;
|
||
|
|
};
|
||
|
|
|
||
|
|
export const getCallPageUrl = (): string | undefined => callPageUrl;
|