Desktop: call page on its own loopback origin, opt-in (#43) #252
Merged
jared
merged 1 commits from 2026-09-29 09:34:49 -04:00
desktop-call-origin into lotus
No Reviewers
Labels
Clear labels
a11y
area: appearance
area: auth-session
area: build-ci
area: calls
area: desktop
area: media
area: messaging
area: mobile
area: moderation
area: navigation
area: notifications
area: settings
area: threads
bug
dependencies
docs
duplicate
enhancement
help wanted
invalid
needs-human-review
performance
planning
priority: critical
priority: high
priority: low
priority: medium
qa
question
research
security
tech-debt
ux
wontfix
Accessibility: keyboard, screen reader, contrast, motion
Client area: appearance
Client area: auth-session
Client area: build-ci
Client area: calls
Client area: desktop
Client area: media
Client area: messaging
Client area: mobile
Client area: moderation
Client area: navigation
Client area: notifications
Client area: settings
Client area: threads
Something is not working
Third-party package versions and advisories
README / LOTUS_* docs wrong or missing
This issue or pull request already exists
New feature
Need some help
Something is wrong
Re-render storms, leaks, heavy work on hot paths
Data loss, security hole, or crash on a main path
Broken feature or serious usability problem
Minor issue or polish
Wrong behaviour in an edge case or notable degradation
Manual QA: shipped, needs a human in a real environment
More information is needed
XSS, unsafe URLs, data leaks, auth/session
Code health, dead code, fragile patterns
Usability or visual inconsistency
This won't be fixed
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: LotusGuild/cinny#252
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Part of #43, for the desktop app. The web moved the call page to
call.chat.lotusguild.org. The desktop app still loads the bundled call page from its own origin (http://localhost:44548), so the call frame can read the app'slocalStorage(login token) and DOM.Change
http://127.0.0.1:<port>. That's the same server and bundle, but a different origin, and still a secure context. The newresolveDesktopCallPageUrlloads the bundled call page from there when the desktop config setsdesktopCallOrigin.http://127.0.0.1origin on the same port as the app is accepted, with no path, query or credentials. It applies only when the app itself runs onhttp://localhost(release builds).desktopCallOrigin, together with the server bind, CSP and permission changes it needs (cinny-desktop PR, linked below).Tested
Simulated desktop app: Tauri bridge stub plus the desktop
config.json, served on bothlocalhostand127.0.0.1, against a local Synapse + LiveKit with two users. Chromium is the Windows (WebView2) engine.http://127.0.0.1:44600http://localhost:44600parent.localStorage/parent.documentfrom the frameThe misses were the same on both sides: the local LiveKit connection ("Couldn't connect to voice").
Not tested: a real call in the Windows app. That's needed on the cinny-desktop PR before it merges.
🤖 Generated with Claude Code
https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA