fix(desktop): isolate remote runtime auth and embeds
Fix remote Desktop runtime bootstrapping across context-panel session chats, additional windows, and host switches.\n\n- Bootstrap embedded session-chat frames through a same-origin parent handshake that supplies the active endpoint, bearer token, runtime headers, local origin, and a credential-free relay descriptor.\n- Keep relay pairing grants out of iframe state and explicitly rebind the SDK after embedded bootstrap or relay restoration.\n- Preserve each additional and Mini Chat window's own init script instead of overwriting it when the main window's host configuration changes.\n- Replace direct iframe global calls with same-origin postMessage synchronization for theme, chat settings, and visibility.\n\nHarden Desktop host authentication and probing.\n\n- Bind password, passkey, session-status, and token-persistence completions to the runtime identity that started them, so a late result cannot alter a newly selected host.\n- Cancel active passkey operations and reset transient auth UI state on endpoint changes.\n- Verify stored client authentication via /auth/session for direct and relay host probes, distinguishing reachable hosts from hosts that require re-authentication.\n- Bound every relay probe request with an aborting timeout so a stalled auth request cannot hang refresh or host switching.\n\nAdd regression coverage for the embedded bootstrap handshake, credential-free relay descriptor exposure, runtime configuration, stale password completion after an A-to-B switch, and SDK errors that carry a zero response status.\n\nAlso preserve SDK response status on session-message loader errors so callers can distinguish transport and server failures.
This commit is contained in:
+22
-14
@@ -4,6 +4,10 @@ import { registerSW } from 'virtual:pwa-register';
|
||||
import type { RuntimeAPIs } from '@openchamber/ui/lib/api/types';
|
||||
import { getStoredMobileLayoutPreference } from '@openchamber/ui/lib/mobileLayoutPreference';
|
||||
import type { HostedSurface } from '@openchamber/ui/lib/runtimeSurface';
|
||||
import {
|
||||
isEmbeddedSessionChat,
|
||||
requestEmbeddedSessionRuntimeBootstrap,
|
||||
} from '@openchamber/ui/components/layout/contextPanelEmbeddedChat';
|
||||
import '@openchamber/ui/index.css';
|
||||
import '@openchamber/ui/styles/fonts';
|
||||
|
||||
@@ -14,8 +18,6 @@ declare global {
|
||||
}
|
||||
}
|
||||
|
||||
window.__OPENCHAMBER_RUNTIME_APIS__ = createConfiguredWebAPIs();
|
||||
|
||||
const isCoarsePointer = (): boolean => {
|
||||
if (typeof window === 'undefined' || typeof window.matchMedia !== 'function') {
|
||||
return false;
|
||||
@@ -104,18 +106,24 @@ const unregisterDevelopmentServiceWorkers = (): void => {
|
||||
});
|
||||
};
|
||||
|
||||
if (hostedSurface === 'mobile') {
|
||||
void import('@openchamber/ui/apps/renderMobileApp')
|
||||
.then(({ renderMobileApp }) => {
|
||||
renderMobileApp(window.__OPENCHAMBER_RUNTIME_APIS__ ?? createConfiguredWebAPIs());
|
||||
});
|
||||
} else {
|
||||
// Hold the render (HTML splash stays up) until a desktop relay-host restore
|
||||
// has picked its transport — otherwise the app boots against a not-yet-chosen
|
||||
// endpoint and flashes the auth screen before the tunnel connects. Resolves
|
||||
// immediately when no relay host is involved.
|
||||
void getDesktopRelayRestoreReady().then(() => import('@openchamber/ui/main'));
|
||||
}
|
||||
const start = async (): Promise<void> => {
|
||||
const embeddedBootstrap = isEmbeddedSessionChat()
|
||||
? await requestEmbeddedSessionRuntimeBootstrap()
|
||||
: null;
|
||||
window.__OPENCHAMBER_RUNTIME_APIS__ = createConfiguredWebAPIs(embeddedBootstrap);
|
||||
|
||||
if (hostedSurface === 'mobile') {
|
||||
const { renderMobileApp } = await import('@openchamber/ui/apps/renderMobileApp');
|
||||
renderMobileApp(window.__OPENCHAMBER_RUNTIME_APIS__);
|
||||
return;
|
||||
}
|
||||
|
||||
// Hold the render until a desktop relay-host restore has picked its transport.
|
||||
await getDesktopRelayRestoreReady();
|
||||
await import('@openchamber/ui/main');
|
||||
};
|
||||
|
||||
void start();
|
||||
|
||||
if (import.meta.env.PROD) {
|
||||
registerPwaServiceWorker();
|
||||
|
||||
Reference in New Issue
Block a user