feat(desktop): call page on its own loopback origin, opt-in (#43)
CI / Build & Quality Checks (pull_request) Successful in 1m46s
CI / Trigger Desktop Build (pull_request) Skipped
CI / Docker image build & smoke test (pull_request) Skipped
CI / Secret scan (gitleaks) (pull_request) Successful in 8s
CI / Playwright smoke (e2e) (pull_request) Successful in 10m24s
CI / Build & Quality Checks (pull_request) Successful in 1m46s
CI / Trigger Desktop Build (pull_request) Skipped
CI / Docker image build & smoke test (pull_request) Skipped
CI / Secret scan (gitleaks) (pull_request) Successful in 8s
CI / Playwright smoke (e2e) (pull_request) Successful in 10m24s
The desktop app loads the bundled Element Call page from its own origin (http://localhost:<port>), so the call frame can read the app's storage (login token) and DOM — the hole #43 closed on the web by moving the page to call.chat.lotusguild.org. The desktop's local server can also answer on http://127.0.0.1:<port>: the same server and bundle, but a different origin (and still a secure context). resolveDesktopCallPageUrl loads the bundled page from there when the desktop config sets `desktopCallOrigin`: - only a loopback http origin on the SAME port as the app, no path, query or credentials; - only when the app itself runs on http://localhost (release builds; debug builds on tauri:// keep the same-origin page); - unset (every desktop build until cinny-desktop opts in, together with the server bind, CSP and permission changes it needs): unchanged. The web app is unchanged (elementCallUrl as before). Tested in a simulated desktop app (Tauri bridge stub + the desktop config.json, served on localhost and 127.0.0.1) against a local Synapse + LiveKit, two users: call page from http://127.0.0.1:<port>, parentUrl = the app origin; the frame gets SecurityError on parent.localStorage and parent.document (same-origin control: readable); join, speaking indicator, mic off/on, screenshare start/stop, layout switch and hang-up all work, no page errors — 12/12 in 5 of 6 runs, like the same-origin control (3 of 4; the misses on both sides were the local LiveKit connection). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
91f82d60e3
commit
7d7a379ce0
+14
-2
@@ -36,7 +36,11 @@ import { applyCustomAccent, removeCustomAccent } from '../utils/accentColor';
|
||||
import { zIndices } from '../styles/zIndex';
|
||||
import { OIDC_CALLBACK_PATH } from './paths';
|
||||
import { OidcCallback } from './auth/oidc/OidcCallback';
|
||||
import { resolveCallPageUrl, setCallPageUrl } from '../plugins/call/callPageUrl';
|
||||
import {
|
||||
resolveCallPageUrl,
|
||||
resolveDesktopCallPageUrl,
|
||||
setCallPageUrl,
|
||||
} from '../plugins/call/callPageUrl';
|
||||
|
||||
// The emoji families (Twemoji when "Twitter emoji" is on, Twemoji flags on
|
||||
// Windows — see SystemEmojiFeature) must sit before the generic family, or the
|
||||
@@ -223,7 +227,15 @@ function App() {
|
||||
>
|
||||
{(clientConfig) => {
|
||||
// [Gitea #43] Idempotent: where the call page is loaded from.
|
||||
setCallPageUrl(resolveCallPageUrl(clientConfig.elementCallUrl, isTauri()));
|
||||
setCallPageUrl(
|
||||
isTauri()
|
||||
? resolveDesktopCallPageUrl(
|
||||
clientConfig.desktopCallOrigin,
|
||||
window.location.origin,
|
||||
import.meta.env.BASE_URL,
|
||||
)
|
||||
: resolveCallPageUrl(clientConfig.elementCallUrl, false),
|
||||
);
|
||||
return (
|
||||
<ClientConfigProvider value={clientConfig}>
|
||||
<QueryClientProvider client={queryClient}>
|
||||
|
||||
Reference in New Issue
Block a user