feat(rooms): Room Widgets (MSC1236 im.vector.modular.widgets)
Phase C.1 of the protocol-gaps roadmap, gate-green (693 tests). Generalizes the Element Call widget host into a general room-widget feature: - StateEvent.Widget + widgetsPanelAtom + useRoomWidgets (WidgetParser). - RoomWidgetView: sandboxed-iframe host via ClientWidgetApi with a conservative GeneralWidgetDriver (approves only benign display caps — no room-event send/read/to-device). Blocks same-origin widget URLs (sandbox breakout guard). - WidgetsPanel: list / open / add / remove, PL-gated on im.vector.modular.widgets, https + non-same-origin URL validation. Mounted like the media gallery (header toggle + 3-way content-panel exclusivity + mobile full-screen overlay). - Tested URL/capability/id helpers. Requires the prod CSP frame-src widening (matrix repo) for external widgets. v1 cuts (capability consent prompt, Jitsi/sticker types, user widgets) noted. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -27,6 +27,9 @@ export enum StateEvent {
|
||||
RoomTopic = 'm.room.topic',
|
||||
RoomAvatar = 'm.room.avatar',
|
||||
RoomPinnedEvents = 'm.room.pinned_events',
|
||||
// [MSC1236] Room widgets (embedded apps). One state event per widget,
|
||||
// state_key = widget id; content is a matrix-widget-api IWidget.
|
||||
Widget = 'im.vector.modular.widgets',
|
||||
RoomEncryption = 'm.room.encryption',
|
||||
RoomHistoryVisibility = 'm.room.history_visibility',
|
||||
// [MSC1763] Per-room message retention policy (disappearing messages).
|
||||
|
||||
Reference in New Issue
Block a user