fix(desktop): isolate remote runtime auth and embeds

Fix remote Desktop runtime bootstrapping across context-panel session chats, additional windows, and host switches.\n\n- Bootstrap embedded session-chat frames through a same-origin parent handshake that supplies the active endpoint, bearer token, runtime headers, local origin, and a credential-free relay descriptor.\n- Keep relay pairing grants out of iframe state and explicitly rebind the SDK after embedded bootstrap or relay restoration.\n- Preserve each additional and Mini Chat window's own init script instead of overwriting it when the main window's host configuration changes.\n- Replace direct iframe global calls with same-origin postMessage synchronization for theme, chat settings, and visibility.\n\nHarden Desktop host authentication and probing.\n\n- Bind password, passkey, session-status, and token-persistence completions to the runtime identity that started them, so a late result cannot alter a newly selected host.\n- Cancel active passkey operations and reset transient auth UI state on endpoint changes.\n- Verify stored client authentication via /auth/session for direct and relay host probes, distinguishing reachable hosts from hosts that require re-authentication.\n- Bound every relay probe request with an aborting timeout so a stalled auth request cannot hang refresh or host switching.\n\nAdd regression coverage for the embedded bootstrap handshake, credential-free relay descriptor exposure, runtime configuration, stale password completion after an A-to-B switch, and SDK errors that carry a zero response status.\n\nAlso preserve SDK response status on session-message loader errors so callers can distinguish transport and server failures.
This commit is contained in:
Bohdan Triapitsyn
2026-07-30 17:43:39 +03:00
parent 4ae3debf54
commit 3b00c91893
19 changed files with 819 additions and 159 deletions
@@ -7,8 +7,36 @@ import {
switchRuntimeEndpoint,
} from './runtime-switch';
import { clearRuntimeUrlAuthToken, setRuntimeExtraHeaders } from './runtime-auth';
import {
activateRelayTunnel,
deactivateRelayTunnel,
getActiveRelayDescriptor,
} from './relay/runtime-tunnel';
describe('runtime endpoint switching', () => {
test('exposes a credential-free copy of the active relay descriptor', () => {
const descriptor = {
relayUrl: 'wss://relay.example.com',
serverId: 'server-1',
hostEncPubJwk: { kty: 'EC', crv: 'P-256', x: 'public-x', y: 'public-y' },
grant: 'one-time-secret',
};
try {
activateRelayTunnel(descriptor);
const exposed = getActiveRelayDescriptor();
expect(exposed).toEqual({
relayUrl: descriptor.relayUrl,
serverId: descriptor.serverId,
hostEncPubJwk: descriptor.hostEncPubJwk,
});
expect(exposed).not.toBe(descriptor);
expect(exposed?.hostEncPubJwk).not.toBe(descriptor.hostEncPubJwk);
} finally {
deactivateRelayTunnel();
}
});
test('notifies listeners before and after mutating the active endpoint', () => {
const previousWindow = Object.getOwnPropertyDescriptor(globalThis, 'window');
const previousFetch = globalThis.fetch;