Skip to content

Commit a5d803d

Browse files
committed
chore: update
1 parent 8f7bc49 commit a5d803d

3 files changed

Lines changed: 18 additions & 14 deletions

File tree

‎docs/guide/security.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -105,7 +105,7 @@ Higher-level integrations can drive their own authentication UI instead: disable
105105
WebSocket handshakes from browser extensions and other external viewers carry the viewer's own `Origin` header. A host can authorize that origin through a live registry:
106106

107107
```ts
108-
import { createWsOriginRegistry } from 'devframe/rpc/transports/ws-server'
108+
import { attachWsRpcTransport, createWsOriginRegistry } from 'devframe/rpc/transports/ws-server'
109109

110110
const viewerOrigins = createWsOriginRegistry({
111111
validateOrigin: origin => origin.startsWith('chrome-extension://')

‎packages/hub/src/client/remote.test.ts‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -74,8 +74,9 @@ describe('remote connection URLs', () => {
7474
})
7575

7676
it('preserves the original encoding of hash-route parameters', () => {
77-
expect(stripRemoteConnectionFromUrl(
78-
'https://viewer.example/#/inspect?tab=a%20b&devframe-remote-connection=descriptor',
79-
)).toBe('https://viewer.example/#/inspect?tab=a%20b')
77+
const baseUrl = 'https://viewer.example/#/inspect?tab=a%20b&filter=a+b'
78+
const url = buildRemoteDevframeUrl(baseUrl, connection)
79+
expect(url).toContain('#/inspect?tab=a%20b&filter=a+b&devframe-remote-connection=')
80+
expect(stripRemoteConnectionFromUrl(url)).toBe(baseUrl)
8081
})
8182
})

‎packages/hub/src/remote-url.ts‎

Lines changed: 13 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,16 @@ function base64UrlEncode(value: string): string {
99
return btoa(binary).replace(/\+/g, '-').replace(/\//g, '_').replace(/=+$/, '')
1010
}
1111

12+
function setRemoteConnectionParam(value: string, param: string): string {
13+
const parts = value ? value.split('&') : []
14+
const existingIdx = parts.findIndex(part => part.split('=')[0] === REMOTE_CONNECTION_KEY)
15+
if (existingIdx >= 0)
16+
parts[existingIdx] = param
17+
else
18+
parts.push(param)
19+
return parts.join('&')
20+
}
21+
1222
/** Encode a remote connection descriptor into an external viewer URL. */
1323
export function buildRemoteConnectionUrl(
1424
baseUrl: string,
@@ -31,18 +41,11 @@ export function buildRemoteConnectionUrl(
3141
const routeQueryIdx = rawHash.indexOf('?')
3242
if (routeQueryIdx !== -1) {
3343
const route = rawHash.slice(0, routeQueryIdx + 1)
34-
const params = new URLSearchParams(rawHash.slice(routeQueryIdx + 1))
35-
params.set(REMOTE_CONNECTION_KEY, encoded)
36-
return `${beforeHash}#${route}${params}`
44+
const query = setRemoteConnectionParam(rawHash.slice(routeQueryIdx + 1), param)
45+
return `${beforeHash}#${route}${query}`
3746
}
3847

39-
const parts = rawHash.split('&')
40-
const existingIdx = parts.findIndex(part => part.split('=')[0] === REMOTE_CONNECTION_KEY)
41-
if (existingIdx >= 0)
42-
parts[existingIdx] = param
43-
else
44-
parts.push(param)
45-
return `${beforeHash}#${parts.join('&')}`
48+
return `${beforeHash}#${setRemoteConnectionParam(rawHash, param)}`
4649
}
4750

4851
const hashIdx = baseUrl.indexOf('#')

0 commit comments

Comments
 (0)