* fix(ui): open app deep links from chat after confirmation DOMPurify's default URI policy stripped href from anchors with custom application schemes (obsidian://, vscode://, ...), so every app link rendered in chat was dead across web, desktop, VS Code, and mobile. - Classify safe app-link schemes in lib/url.ts (browser-handled, scriptable, webview-internal, network, and self-deep-link schemes stay excluded) and let openExternalUrl accept them - Keep app-link hrefs through the markdown sanitize hook - Intercept app-link clicks in the markdown renderer and route them through a confirmation dialog (Trust and open / Open once, dismiss to cancel) mounted in the desktop/web app root and the mobile shell - Persist per-device trusted schemes in a zustand store; trusted schemes open without asking again * feat(settings): manage trusted app link schemes in General Add an App links section to Settings > General listing the application schemes trusted on this device with a delete action; removing a scheme restores the confirmation dialog for it. Register the section in settings search. * fix(ui): enforce app link confirmation * fix(ui): handle app links by runtime * fix(vscode): keep app links unsupported * fix(settings): clarify trusted app links --------- Co-authored-by: Bohdan Triapitsyn <artmore@protonmail.com>
68 lines
2.2 KiB
TypeScript
68 lines
2.2 KiB
TypeScript
import { beforeEach, describe, expect, test } from 'bun:test';
|
|
|
|
import { useAppLinkTrustStore } from '@/stores/appLinkTrustStore';
|
|
|
|
import {
|
|
getAppLinkConfirmationSnapshot,
|
|
openAppLinkWithConfirmation,
|
|
settleAppLinkConfirmation,
|
|
} from './appLinkConfirmation';
|
|
|
|
describe('app link confirmation', () => {
|
|
beforeEach(() => {
|
|
useAppLinkTrustStore.setState({ trustedSchemes: [] });
|
|
const pending = getAppLinkConfirmationSnapshot();
|
|
if (pending) {
|
|
settleAppLinkConfirmation('cancel');
|
|
}
|
|
});
|
|
|
|
test('opens trusted schemes without asking', async () => {
|
|
useAppLinkTrustStore.getState().trustScheme('obsidian');
|
|
|
|
await openAppLinkWithConfirmation('obsidian://open?vault=Notebook&file=notes');
|
|
|
|
expect(getAppLinkConfirmationSnapshot()).toBeNull();
|
|
expect(useAppLinkTrustStore.getState().isSchemeTrusted('obsidian')).toBe(true);
|
|
});
|
|
|
|
test('asks once and trusts the scheme when the user chooses trust', async () => {
|
|
const pending = openAppLinkWithConfirmation('linear://issue/ABC-1');
|
|
|
|
expect(getAppLinkConfirmationSnapshot()?.url).toBe('linear://issue/ABC-1');
|
|
|
|
settleAppLinkConfirmation('trust');
|
|
await pending;
|
|
|
|
expect(getAppLinkConfirmationSnapshot()).toBeNull();
|
|
expect(useAppLinkTrustStore.getState().isSchemeTrusted('linear')).toBe(true);
|
|
});
|
|
|
|
test('cancel opens nothing and keeps the scheme untrusted', async () => {
|
|
const pending = openAppLinkWithConfirmation('notion://note/xyz');
|
|
|
|
settleAppLinkConfirmation('cancel');
|
|
await pending;
|
|
|
|
expect(getAppLinkConfirmationSnapshot()).toBeNull();
|
|
expect(useAppLinkTrustStore.getState().isSchemeTrusted('notion')).toBe(false);
|
|
});
|
|
|
|
test('a newer request cancels the pending one', async () => {
|
|
const first = openAppLinkWithConfirmation('obsidian://open?vault=a');
|
|
const firstChoice = first.then(
|
|
() => 'settled',
|
|
() => 'settled',
|
|
);
|
|
const second = openAppLinkWithConfirmation('linear://open/1');
|
|
|
|
expect(await firstChoice).toBe('settled');
|
|
expect(getAppLinkConfirmationSnapshot()?.url).toBe('linear://open/1');
|
|
|
|
settleAppLinkConfirmation('open');
|
|
await second;
|
|
|
|
expect(getAppLinkConfirmationSnapshot()).toBeNull();
|
|
});
|
|
});
|