Files
openchamber/packages/ui/src/lib/url.test.ts
T
ChangeHowandBohdan Triapitsyn 3a78d86248 fix(ui): open app deep links from chat after confirmation (#2932)
* fix(ui): open app deep links from chat after confirmation

DOMPurify's default URI policy stripped href from anchors with custom
application schemes (obsidian://, vscode://, ...), so every app link
rendered in chat was dead across web, desktop, VS Code, and mobile.

- Classify safe app-link schemes in lib/url.ts (browser-handled,
  scriptable, webview-internal, network, and self-deep-link schemes
  stay excluded) and let openExternalUrl accept them
- Keep app-link hrefs through the markdown sanitize hook
- Intercept app-link clicks in the markdown renderer and route them
  through a confirmation dialog (Trust and open / Open once, dismiss
  to cancel) mounted in the desktop/web app root and the mobile shell
- Persist per-device trusted schemes in a zustand store; trusted
  schemes open without asking again

* feat(settings): manage trusted app link schemes in General

Add an App links section to Settings > General listing the application
schemes trusted on this device with a delete action; removing a scheme
restores the confirmation dialog for it. Register the section in
settings search.

* fix(ui): enforce app link confirmation

* fix(ui): handle app links by runtime

* fix(vscode): keep app links unsupported

* fix(settings): clarify trusted app links

---------

Co-authored-by: Bohdan Triapitsyn <artmore@protonmail.com>
2026-08-23 01:53:21 +03:00

63 lines
2.7 KiB
TypeScript

import { describe, expect, test } from 'bun:test';
import { getUrlScheme, isAppLinkUrl } from '@/lib/url';
describe('getUrlScheme', () => {
test('extracts the lowercased scheme', () => {
expect(getUrlScheme('Obsidian://open?vault=X')).toBe('obsidian');
expect(getUrlScheme('https://example.test')).toBe('https');
});
test('returns null for unparseable values', () => {
expect(getUrlScheme('')).toBeNull();
expect(getUrlScheme('not a url')).toBeNull();
});
});
describe('isAppLinkUrl', () => {
test('accepts custom application schemes', () => {
expect(isAppLinkUrl('obsidian://open?vault=Notebook&file=a%20b')).toBe(true);
expect(isAppLinkUrl('vscode://file/path/to/file.ts')).toBe(true);
expect(isAppLinkUrl('linear://issue/ABC-1')).toBe(true);
expect(isAppLinkUrl('notion://note/xyz')).toBe(true);
expect(isAppLinkUrl('slack://channel?id=C123')).toBe(true);
});
test('rejects browser and communication schemes', () => {
expect(isAppLinkUrl('https://example.test')).toBe(false);
expect(isAppLinkUrl('http://example.test')).toBe(false);
expect(isAppLinkUrl('mailto:user@example.test')).toBe(false);
expect(isAppLinkUrl('tel:+1234567890')).toBe(false);
expect(isAppLinkUrl('sms:+1234567890')).toBe(false);
expect(isAppLinkUrl('webcal://example.test/cal.ics')).toBe(false);
});
test('rejects dangerous and internal schemes', () => {
expect(isAppLinkUrl('javascript:alert(1)')).toBe(false);
expect(isAppLinkUrl('data:text/html;base64,PHNjcmlwdD4=')).toBe(false);
expect(isAppLinkUrl('vbscript:msgbox(1)')).toBe(false);
expect(isAppLinkUrl('blob:https://example.test/uuid')).toBe(false);
expect(isAppLinkUrl('about:blank')).toBe(false);
expect(isAppLinkUrl('file:///etc/passwd')).toBe(false);
expect(isAppLinkUrl('ws://localhost:8080')).toBe(false);
expect(isAppLinkUrl('ftp://files.example.test')).toBe(false);
expect(isAppLinkUrl('intent://scan/#Intent;scheme=zxing;end')).toBe(false);
expect(isAppLinkUrl('chrome://settings')).toBe(false);
expect(isAppLinkUrl('devtools://devtools/bundled/inspector.html')).toBe(false);
expect(isAppLinkUrl('ms-msdt:/id%20PCWDiagnostic')).toBe(false);
expect(isAppLinkUrl('search-ms:query=report')).toBe(false);
expect(isAppLinkUrl('shell:AppsFolder')).toBe(false);
});
test('rejects OpenChamber and Capacitor self-deep-links', () => {
expect(isAppLinkUrl('openchamber://connect?host=x')).toBe(false);
expect(isAppLinkUrl('openchamber-ui://app/index.html')).toBe(false);
expect(isAppLinkUrl('capacitor://localhost/index.html')).toBe(false);
});
test('rejects malformed input', () => {
expect(isAppLinkUrl('')).toBe(false);
expect(isAppLinkUrl('random text')).toBe(false);
});
});