CI / Build & Quality Checks (pull_request) Successful in 3m31s
CI / Trigger Desktop Build (pull_request) Skipped
CI / Docker image build & smoke test (pull_request) Skipped
CI / Secret scan (gitleaks) (pull_request) Successful in 12s
CI / Playwright smoke (e2e) (pull_request) Successful in 12m27s
Groundwork for serving the call page from its own origin (call.chat.lotusguild.org). Inert until config.json sets `elementCallUrl`: without it the bundled same-origin page is used exactly as today. - callPageUrl: resolves `elementCallUrl` — absolute https only (http only on localhost for development); anything else, and the desktop app, fall back to the bundled page so a bad value can't break calls. Set once from the loaded client config. - CallEmbed builds the widget URL from it; the widget origin (used by the message guard and Capability Delegation) follows automatically. - Soundboard: a host blob: URL can't be fetched from another origin, so io.lotus.inject_audio now also carries the clip's bytes (`audio`). Forks that predate it ignore the field and use `url`, so this is safe on the released fork. Needs element-call's lotus-call-origin branch (host-origin message check + inject_audio bytes) released and pinned before `elementCallUrl` is set. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
41 lines
1.3 KiB
TypeScript
41 lines
1.3 KiB
TypeScript
import { test } from 'node:test';
|
|
import assert from 'node:assert/strict';
|
|
import { resolveCallPageUrl } from './callPageUrl';
|
|
|
|
const URL_OK = 'https://call.chat.example.org/public/element-call/index.html';
|
|
|
|
test('uses an absolute https URL on the web', () => {
|
|
assert.equal(resolveCallPageUrl(URL_OK, false), URL_OK);
|
|
});
|
|
|
|
test('strips a query or hash (the app adds its own parameters)', () => {
|
|
assert.equal(resolveCallPageUrl(`${URL_OK}?x=1#y`, false), URL_OK);
|
|
});
|
|
|
|
test('allows http only on localhost (development)', () => {
|
|
assert.equal(
|
|
resolveCallPageUrl('http://127.0.0.1:5174/public/element-call/index.html', false),
|
|
'http://127.0.0.1:5174/public/element-call/index.html',
|
|
);
|
|
assert.equal(resolveCallPageUrl('http://call.example.org/index.html', false), undefined);
|
|
});
|
|
|
|
test('desktop keeps the bundled page', () => {
|
|
assert.equal(resolveCallPageUrl(URL_OK, true), undefined);
|
|
});
|
|
|
|
test('anything else falls back to the bundled page', () => {
|
|
[
|
|
undefined,
|
|
null,
|
|
42,
|
|
'',
|
|
' ',
|
|
'not a url',
|
|
'/public/element-call/index.html',
|
|
'http://call.chat.example.org/index.html',
|
|
['javascript', 'alert(1)'].join(':'),
|
|
'data:text/html,x',
|
|
].forEach((v) => assert.equal(resolveCallPageUrl(v, false), undefined, String(v)));
|
|
});
|