fix(desktop): isolate remote runtime auth and embeds
Fix remote Desktop runtime bootstrapping across context-panel session chats, additional windows, and host switches.\n\n- Bootstrap embedded session-chat frames through a same-origin parent handshake that supplies the active endpoint, bearer token, runtime headers, local origin, and a credential-free relay descriptor.\n- Keep relay pairing grants out of iframe state and explicitly rebind the SDK after embedded bootstrap or relay restoration.\n- Preserve each additional and Mini Chat window's own init script instead of overwriting it when the main window's host configuration changes.\n- Replace direct iframe global calls with same-origin postMessage synchronization for theme, chat settings, and visibility.\n\nHarden Desktop host authentication and probing.\n\n- Bind password, passkey, session-status, and token-persistence completions to the runtime identity that started them, so a late result cannot alter a newly selected host.\n- Cancel active passkey operations and reset transient auth UI state on endpoint changes.\n- Verify stored client authentication via /auth/session for direct and relay host probes, distinguishing reachable hosts from hosts that require re-authentication.\n- Bound every relay probe request with an aborting timeout so a stalled auth request cannot hang refresh or host switching.\n\nAdd regression coverage for the embedded bootstrap handshake, credential-free relay descriptor exposure, runtime configuration, stale password completion after an A-to-B switch, and SDK errors that carry a zero response status.\n\nAlso preserve SDK response status on session-message loader errors so callers can distinguish transport and server failures.
This commit is contained in:
@@ -409,19 +409,34 @@ export const desktopInstallIdGet = async (): Promise<string> => {
|
||||
|
||||
const RELAY_PROBE_TIMEOUT_MS = 8_000;
|
||||
|
||||
const fetchRelayProbe = async (
|
||||
tunnel: ReturnType<typeof createRelayTunnelClient>,
|
||||
path: string,
|
||||
init?: RequestInit,
|
||||
): Promise<Response> => {
|
||||
const controller = new AbortController();
|
||||
const timer = window.setTimeout(() => controller.abort(), RELAY_PROBE_TIMEOUT_MS);
|
||||
try {
|
||||
return await tunnel.fetch(path, { ...init, signal: controller.signal });
|
||||
} finally {
|
||||
window.clearTimeout(timer);
|
||||
}
|
||||
};
|
||||
|
||||
/**
|
||||
* Reachability check for a relay host: open a throwaway E2EE tunnel and hit
|
||||
* /health. Relay hosts have no HTTP address for `desktopHostProbe`. Hard
|
||||
* timeout: a ghost relay registration (relay lost the host, host doesn't know)
|
||||
* leaves the tunnel in `connecting` forever — the probe must report
|
||||
* unreachable instead of hanging every status/switch flow with it.
|
||||
* Reachability and client-auth check for a relay host: open a throwaway E2EE
|
||||
* tunnel, verify `/health`, then verify `/auth/session` with the saved bearer.
|
||||
* Relay hosts have no HTTP address for `desktopHostProbe`. Hard timeout: a
|
||||
* ghost relay registration (relay lost the host, host doesn't know) leaves the
|
||||
* tunnel in `connecting` forever — the probe must report unreachable instead
|
||||
* of hanging every status/switch flow with it.
|
||||
*/
|
||||
export const probeRelayDesktopHost = async (
|
||||
relay: DesktopHostRelay,
|
||||
// With `keepTunnel`, an 'ok' probe RETURNS its live tunnel (the caller owns
|
||||
// it — typically adopting it as the runtime tunnel, skipping a second
|
||||
// WebSocket connect + E2EE handshake); every other outcome closes it.
|
||||
options?: { keepTunnel?: boolean },
|
||||
options?: { keepTunnel?: boolean; clientToken?: string | null; requestHeaders?: Record<string, string> | null },
|
||||
): Promise<HostProbeResult & { tunnel?: ReturnType<typeof createRelayTunnelClient> }> => {
|
||||
const tunnel = createRelayTunnelClient({
|
||||
relayUrl: relay.relayUrl,
|
||||
@@ -431,16 +446,19 @@ export const probeRelayDesktopHost = async (
|
||||
const startedAt = Date.now();
|
||||
let keep = false;
|
||||
try {
|
||||
const response = await Promise.race([
|
||||
tunnel.fetch('/health'),
|
||||
new Promise<null>((resolve) => {
|
||||
const timer = window.setTimeout(() => resolve(null), RELAY_PROBE_TIMEOUT_MS);
|
||||
if (typeof timer !== 'number' && typeof (timer as { unref?: () => void }).unref === 'function') {
|
||||
(timer as unknown as { unref: () => void }).unref();
|
||||
}
|
||||
}),
|
||||
]);
|
||||
if (!response?.ok) return { status: 'unreachable', latencyMs: 0 };
|
||||
const response = await fetchRelayProbe(tunnel, '/health');
|
||||
if (!response.ok) return { status: 'unreachable', latencyMs: 0 };
|
||||
const headers = new Headers({ Accept: 'application/json' });
|
||||
for (const [name, value] of Object.entries(options?.requestHeaders || {})) {
|
||||
if (name.toLowerCase() !== 'authorization') headers.set(name, value);
|
||||
}
|
||||
const clientToken = options?.clientToken?.trim();
|
||||
if (clientToken) headers.set('Authorization', `Bearer ${clientToken}`);
|
||||
const sessionResponse = await fetchRelayProbe(tunnel, '/auth/session', { headers });
|
||||
if (sessionResponse.status === 401 || sessionResponse.status === 403) {
|
||||
return { status: 'auth', latencyMs: Math.max(0, Date.now() - startedAt) };
|
||||
}
|
||||
if (!sessionResponse.ok) return { status: 'unreachable', latencyMs: 0 };
|
||||
keep = options?.keepTunnel === true;
|
||||
return { status: 'ok', latencyMs: Math.max(0, Date.now() - startedAt), ...(keep ? { tunnel } : {}) };
|
||||
} catch {
|
||||
|
||||
Reference in New Issue
Block a user