feat: browser-side annotation screenshots for web preview
Capture the preview/browser iframe DOM with snapDOM (html-to-image fallback) so web annotation screenshots match the visible viewport, without a headless Chromium dependency. - Preserve document scroll via viewport crop and re-bake nested scroll (e.g. the Starlight sidebar) deterministically on the clone - Pin position:fixed elements to their measured viewport rect so headers and sidebars land correctly in the crop - Extract preview capture/proxy helpers into lib/preview/screenshot-capture.ts to slim down ContextPanel - Guard the external preview proxy against SSRF to private, loopback and reserved/link-local addresses (incl. cloud metadata) - Fully validate preview bridge messages before formatting/use - Warn on the empty browser tab that pages run with full access, so users browse untrusted sites knowingly
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
import { describe, expect, it } from 'vitest';
|
||||
|
||||
import { classifyPreviewNavigation, classifyPreviewResourceError, rewritePreviewBody } from './proxy-runtime.js';
|
||||
import { classifyPreviewNavigation, classifyPreviewResourceError, normalizeProxyTargetUrl, rewritePreviewBody } from './proxy-runtime.js';
|
||||
|
||||
const rewrite = (bodyText, kind) => rewritePreviewBody({
|
||||
bodyText,
|
||||
@@ -128,6 +128,17 @@ describe('preview navigation policy', () => {
|
||||
});
|
||||
});
|
||||
|
||||
it('maps app-origin root links back to the upstream origin while proxied', () => {
|
||||
expect(classifyPreviewNavigation({
|
||||
url: 'http://127.0.0.1:57123/support',
|
||||
currentUrl,
|
||||
targetOrigin: 'https://openchamber.dev',
|
||||
})).toEqual({
|
||||
action: 'proxy',
|
||||
url: 'https://openchamber.dev/support',
|
||||
});
|
||||
});
|
||||
|
||||
it('sends non-loopback http links outside the preview iframe', () => {
|
||||
expect(classifyPreviewNavigation({ url: 'https://example.com/docs', currentUrl })).toEqual({
|
||||
action: 'external',
|
||||
@@ -142,3 +153,37 @@ describe('preview navigation policy', () => {
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
describe('proxy target normalization (SSRF guard)', () => {
|
||||
it('allows ordinary external hosts when allowExternal is set', () => {
|
||||
expect(normalizeProxyTargetUrl('https://docs.openchamber.dev/security/', { allowExternal: true }))
|
||||
.toEqual({ ok: true, origin: 'https://docs.openchamber.dev' });
|
||||
});
|
||||
|
||||
it('rejects non-loopback hosts without allowExternal', () => {
|
||||
expect(normalizeProxyTargetUrl('https://example.com/', {}).ok).toBe(false);
|
||||
});
|
||||
|
||||
it('refuses private, loopback and link-local literals on the external path', () => {
|
||||
for (const url of [
|
||||
'http://127.0.0.1/',
|
||||
'http://10.0.0.5/',
|
||||
'http://172.16.9.9/',
|
||||
'http://192.168.1.1/',
|
||||
'http://169.254.169.254/latest/meta-data/',
|
||||
'http://100.64.0.1/',
|
||||
'http://localhost/',
|
||||
'http://service.local/',
|
||||
'http://[::1]/',
|
||||
'http://[fd00::1]/',
|
||||
'http://[fe80::1]/',
|
||||
'http://2130706433/', // decimal form of 127.0.0.1, normalized by WHATWG URL
|
||||
]) {
|
||||
expect(normalizeProxyTargetUrl(url, { allowExternal: true }).ok, url).toBe(false);
|
||||
}
|
||||
});
|
||||
|
||||
it('still blocks private hosts even via IPv4-mapped IPv6', () => {
|
||||
expect(normalizeProxyTargetUrl('http://[::ffff:127.0.0.1]/', { allowExternal: true }).ok).toBe(false);
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user