Draft generic audio manifest admission and public media adapter
This commit is contained in:
@@ -6,6 +6,7 @@ const fixture = vi.hoisted(() => ({
|
||||
player: { updateExternal: vi.fn(), detachExternal: vi.fn(), releaseExternal: vi.fn(), setExternalVisible: vi.fn() },
|
||||
launcher: { mediaAppId: 'node-demo-v4v' as string | null, panelAppId: null as string | null, openSession: vi.fn() },
|
||||
}))
|
||||
vi.mock('@/stores/app', () => ({useAppStore:()=>({data:{'package-data':{'node-demo-v4v':{manifest:{version:'1'}}}}})}))
|
||||
vi.mock('../useAudioPlayer', () => ({ useAudioPlayer: () => fixture.player }))
|
||||
vi.mock('@/stores/appLauncher', () => ({ useAppLauncherStore: () => fixture.launcher }))
|
||||
vi.mock('@/views/discover/curatedApps', () => ({ appHasMediaBridge: () => fixture.allowed }))
|
||||
@@ -49,3 +50,15 @@ describe('app media session boundary', () => {
|
||||
expect(child.postMessage.mock.calls[child.postMessage.mock.calls.length - 1]![0]).toMatchObject({ command: 'pause' })
|
||||
})
|
||||
})
|
||||
|
||||
it('retains controls and cleanup after catalog expiry but does not admit a new session',()=>{
|
||||
const child={postMessage:vi.fn()};let bridge!:ReturnType<typeof useAppMediaBridge>
|
||||
const wrapper=mount(defineComponent({setup(){bridge=useAppMediaBridge(ref('node-demo-v4v'),ref('https://node.test:7475/'),shallowRef({contentWindow:child} as unknown as HTMLIFrameElement),ref(false));return()=>null}}))
|
||||
fixture.allowed=true;bridge.connect();const session=child.postMessage.mock.calls[0]![0].session
|
||||
fixture.allowed=false
|
||||
bridge.handle({source:child,origin:'https://node.test:7475',data:{type:'archipelago:media-state',version:1,session,available:true,title:'Song',artist:'Artist',playing:true,position:1,duration:10}} as unknown as MessageEvent)
|
||||
const controller=fixture.player.updateExternal.mock.lastCall![0];controller.pause();expect(child.postMessage.mock.lastCall![0].command).toBe('pause')
|
||||
wrapper.unmount();expect(child.postMessage.mock.lastCall![0].command).toBe('pause')
|
||||
const outsider={postMessage:vi.fn()};const denied=mount(defineComponent({setup(){const b=useAppMediaBridge(ref('node-demo-v4v'),ref('https://node.test:7475/'),shallowRef({contentWindow:outsider} as unknown as HTMLIFrameElement),ref(false));b.connect();return()=>null}}))
|
||||
expect(outsider.postMessage).not.toHaveBeenCalled();denied.unmount()
|
||||
})
|
||||
|
||||
@@ -1,21 +1,41 @@
|
||||
import { onBeforeUnmount, watch, type Ref } from 'vue'
|
||||
import { appHasMediaBridge } from '@/views/discover/curatedApps'
|
||||
import { useAudioPlayer, type ExternalAudioState } from './useAudioPlayer'
|
||||
import { useAppStore } from '@/stores/app'
|
||||
import { useAppLauncherStore } from '@/stores/appLauncher'
|
||||
|
||||
export function useAppMediaBridge(appId: Ref<string>, url: Ref<string>, frame: Ref<HTMLIFrameElement | null>, visible: Ref<boolean>) {
|
||||
const player = useAudioPlayer()
|
||||
const launcher = useAppLauncherStore()
|
||||
const app = useAppStore()
|
||||
const installedVersion = () => app.data?.['package-data']?.[appId.value]?.manifest?.version
|
||||
let admitted: { source: Window; origin: string; appId: string; version: string } | null = null
|
||||
const session = Array.from(crypto.getRandomValues(new Uint8Array(16)), byte => byte.toString(16).padStart(2, '0')).join('')
|
||||
const id = `${appId.value}:${session}`
|
||||
const origin = () => { try { return new URL(url.value, window.location.origin).origin } catch { return '' } }
|
||||
function matchesAdmission() {
|
||||
return admitted !== null && admitted.source === frame.value?.contentWindow && admitted.origin === origin()
|
||||
&& admitted.appId === appId.value && admitted.version === installedVersion()
|
||||
}
|
||||
function release() {
|
||||
// Catalog expiry/removal cannot revoke our ability to stop an already
|
||||
// admitted session. The old nonce/source/origin still constrain cleanup.
|
||||
admitted?.source.postMessage({type:'archipelago:media-control',version:1,session,command:'pause'}, admitted.origin)
|
||||
admitted = null
|
||||
player.releaseExternal(id)
|
||||
}
|
||||
function command(command: string, position?: number) {
|
||||
if (!appHasMediaBridge(appId.value) || !origin()) return
|
||||
frame.value?.contentWindow?.postMessage({ type: 'archipelago:media-control', version: 1, session, command, position }, origin())
|
||||
if (!matchesAdmission()) return
|
||||
admitted!.source.postMessage({ type: 'archipelago:media-control', version: 1, session, command, position }, admitted!.origin)
|
||||
}
|
||||
function connect() {
|
||||
if (!appHasMediaBridge(appId.value) || !origin()) return
|
||||
frame.value?.contentWindow?.postMessage({ type: 'archipelago:media-connect', version: 1, session }, origin())
|
||||
if (admitted && !matchesAdmission()) release()
|
||||
if (!admitted) {
|
||||
const version = installedVersion(), source = frame.value?.contentWindow
|
||||
if (!version || !source || !origin() || !appHasMediaBridge(appId.value, version)) return
|
||||
admitted = {source,origin:origin(),appId:appId.value,version}
|
||||
}
|
||||
admitted.source.postMessage({ type: 'archipelago:media-connect', version: 1, session }, admitted.origin)
|
||||
}
|
||||
const controller = { id, play: () => command('play'), pause: () => command('pause'), seek: (position: number) => command('seek', position),
|
||||
next: () => command('next'), previous: () => command('previous'), shuffle: () => command('shuffle'),
|
||||
@@ -24,11 +44,11 @@ export function useAppMediaBridge(appId: Ref<string>, url: Ref<string>, frame: R
|
||||
},
|
||||
}
|
||||
function handle(event: MessageEvent) {
|
||||
if (!appHasMediaBridge(appId.value) || event.source !== frame.value?.contentWindow || event.origin !== origin()) return
|
||||
if (event.source !== frame.value?.contentWindow || event.origin !== origin()) return
|
||||
const data = event.data
|
||||
if (data?.version !== 1) return
|
||||
if (data.type === 'archipelago:media-ready') { connect(); return }
|
||||
if (data.type !== 'archipelago:media-state' || data.session !== session) return
|
||||
if (!matchesAdmission() || data.type !== 'archipelago:media-state' || data.session !== session) return
|
||||
if (data.available !== true) { player.detachExternal(id); return }
|
||||
if (typeof data.title !== 'string' || typeof data.artist !== 'string' || typeof data.playing !== 'boolean'
|
||||
|| !Number.isFinite(data.position) || !Number.isFinite(data.duration) || data.position < 0 || data.duration < 0) return
|
||||
@@ -44,6 +64,7 @@ export function useAppMediaBridge(appId: Ref<string>, url: Ref<string>, frame: R
|
||||
player.updateExternal(controller, state, visible.value)
|
||||
}
|
||||
watch(visible, shown => player.setExternalVisible(id, shown))
|
||||
onBeforeUnmount(() => { command('pause'); player.releaseExternal(id) })
|
||||
watch([appId, url, frame, installedVersion], () => { if (admitted && !matchesAdmission()) release() }, {flush:'sync'})
|
||||
onBeforeUnmount(release)
|
||||
return { connect, handle }
|
||||
}
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
import { appHasMediaBridge, ensureNodeAppAvailable, nodeAppIsAvailable } from '@/views/discover/curatedApps'
|
||||
import { appHasMediaBridge, appRequiresHostFrame, appLaunchPolicyLoaded, ensureAppLaunchPolicy, ensureNodeAppAvailable, nodeAppIsAvailable } from '@/views/discover/curatedApps'
|
||||
import { defineStore } from 'pinia'
|
||||
import { ref, watch, onScopeDispose } from 'vue'
|
||||
import { rpcClient } from '@/api/rpc-client'
|
||||
@@ -237,7 +237,7 @@ export const useAppLauncherStore = defineStore('appLauncher', () => {
|
||||
// phone controls and better performance. Apps with manifest-declared host
|
||||
// integrations stay in the dashboard frame so their parent bridge remains
|
||||
// connected (for example GitWorkshop's consent-gated NIP-07 provider).
|
||||
if (!IS_DEMO && isCompanionApp() && !HOST_FRAME_APPS.has(appId) && !appHasMediaBridge(appId)) {
|
||||
if (!IS_DEMO && isCompanionApp() && !HOST_FRAME_APPS.has(appId) && !appRequiresHostFrame(appId, pkg?.manifest.version) && !appHasMediaBridge(appId, pkg?.manifest.version)) {
|
||||
const runtimeUrl = useAppStore().data?.['package-data']?.[appId]?.installed?.['interface-addresses']?.main?.['lan-address'] || undefined
|
||||
const launchUrl = directAppUrl(appId) || resolveAppUrl(appId, opts.path, runtimeUrl)
|
||||
if (launchUrl) {
|
||||
@@ -274,7 +274,7 @@ export const useAppLauncherStore = defineStore('appLauncher', () => {
|
||||
// page never changes: panel mode renders beside the page, overlay and
|
||||
// fullscreen modes render above it (AppSession styles per display mode).
|
||||
// Closing always returns the user exactly where they launched from.
|
||||
if (appHasMediaBridge(appId)) mediaAppId.value = appId
|
||||
if (pkg && appHasMediaBridge(appId, pkg.manifest.version)) mediaAppId.value = appId
|
||||
panelPath.value = opts.path ?? null
|
||||
panelAppId.value = appId
|
||||
}
|
||||
@@ -282,7 +282,7 @@ export const useAppLauncherStore = defineStore('appLauncher', () => {
|
||||
/** One launch gate for Home, My Apps, Discover, Spotlight and details.
|
||||
* Previously each Apps view owned a private modal, so Home skipped the
|
||||
* Portainer first-run token entirely. */
|
||||
function openSession(appId: string, opts: LaunchOptions = {}) {
|
||||
function openSession(appId: string, opts: LaunchOptions = {}, checkedPolicy = false) {
|
||||
const generation = ++launchGeneration
|
||||
if (appId.startsWith('node-demo-') && !nodeAppIsAvailable(appId)) {
|
||||
useToast().info('Loading this node’s demo app…')
|
||||
@@ -296,6 +296,10 @@ export const useAppLauncherStore = defineStore('appLauncher', () => {
|
||||
})
|
||||
return
|
||||
}
|
||||
if (!IS_DEMO && !appId.startsWith('node-demo-') && !checkedPolicy && !appLaunchPolicyLoaded()) {
|
||||
void ensureAppLaunchPolicy().then(() => { if (generation === launchGeneration) openSession(appId, opts, true) })
|
||||
return
|
||||
}
|
||||
// Home/goal/deep-link launchers do not pass through AppCard.canLaunch.
|
||||
// Apply the same readiness gate here so a container that has just entered
|
||||
// `running` cannot race nginx and show a transient 502 to the user.
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
import {afterEach,describe,expect,it,vi} from 'vitest'
|
||||
import {__setSignedCatalogForTests,appHasMediaBridge,appRequiresHostFrame,ensureAppLaunchPolicy} from '../curatedApps'
|
||||
afterEach(()=>{__setSignedCatalogForTests(null);vi.unstubAllGlobals()})
|
||||
describe('generic manifest media eligibility',()=>{
|
||||
it('accepts a verified ordinary catalog app at its installed version',()=>{
|
||||
__setSignedCatalogForTests({apps:{'public-audio':{version:'2',manifest:{app:{id:'public-audio',metadata:{launch:{media_controls:'archipelago-v1',requires_host_frame:true}}}}}}})
|
||||
expect(appHasMediaBridge('public-audio','2')).toBe(true);expect(appRequiresHostFrame('public-audio','2')).toBe(true)
|
||||
expect(appHasMediaBridge('public-audio','1')).toBe(false)
|
||||
})
|
||||
it('does not grant a public catalog authority over node-only demos or conflicting launch policy',()=>{
|
||||
__setSignedCatalogForTests({apps:{'node-demo-injected':{version:'1',manifest:{app:{id:'node-demo-injected',metadata:{launch:{media_controls:'archipelago-v1'}}}}},bad:{version:'1',manifest:{app:{id:'bad',metadata:{launch:{media_controls:'archipelago-v1',open_in_new_tab:true}}}}}}})
|
||||
expect(appHasMediaBridge('node-demo-injected','1')).toBe(false);expect(appHasMediaBridge('bad','1')).toBe(false)
|
||||
})
|
||||
it('loads only the authenticated verified endpoint before first launch',async()=>{
|
||||
const fetcher=vi.fn(async(_url:string,_init?:RequestInit)=>({ok:true,json:async()=>({apps:{music:{version:'1',manifest:{app:{id:'music',metadata:{launch:{media_controls:'archipelago-v1'}}}}}}})}))
|
||||
vi.stubGlobal('fetch',fetcher);await Promise.all([ensureAppLaunchPolicy(),ensureAppLaunchPolicy()])
|
||||
expect(fetcher).toHaveBeenCalledTimes(1);expect(fetcher.mock.calls[0]?.[0]).toBe('/api/app-catalog');expect(appHasMediaBridge('music','1')).toBe(true)
|
||||
})
|
||||
})
|
||||
@@ -68,7 +68,7 @@ export interface SignedAppEntry {
|
||||
description?: string
|
||||
category?: string
|
||||
container?: { image?: string }
|
||||
metadata?: { icon?: string; author?: string; repo?: string; launch?: { media_controls?: string } }
|
||||
metadata?: { icon?: string; author?: string; repo?: string; launch?: { media_controls?: string; requires_host_frame?: boolean; open_in_new_tab?: boolean } }
|
||||
ports?: { host?: number | string; container?: number | string; auth?: string }[]
|
||||
}
|
||||
}
|
||||
@@ -110,8 +110,41 @@ let nodeCatalogRequest: Promise<SignedAppCatalog | null> | null = null
|
||||
export function nodeAppIsAvailable(id: string): boolean {
|
||||
return nodeCatalogExpires > Date.now() && Boolean(nodeCatalogCache?.apps[id])
|
||||
}
|
||||
export function appHasMediaBridge(id: string): boolean {
|
||||
return nodeAppIsAvailable(id) && nodeCatalogCache?.apps[id]?.manifest?.app?.metadata?.launch?.media_controls === 'archipelago-v1'
|
||||
function verifiedLaunchEntry(id: string): SignedAppEntry | undefined {
|
||||
// Node-only app names never acquire authority from the public catalog.
|
||||
const entry = id.startsWith('node-demo-')
|
||||
? (nodeAppIsAvailable(id) ? nodeCatalogCache?.apps[id] : undefined)
|
||||
: signedCatalogCache?.apps[id]
|
||||
return entry?.manifest?.app?.id === id ? entry : undefined
|
||||
}
|
||||
export function appHasMediaBridge(id: string, installedVersion?: string): boolean {
|
||||
const entry = verifiedLaunchEntry(id)
|
||||
if (!entry || (installedVersion !== undefined && entry.version !== installedVersion)) return false
|
||||
const launch = entry.manifest?.app?.metadata?.launch
|
||||
return launch?.media_controls === 'archipelago-v1' && launch.open_in_new_tab !== true
|
||||
}
|
||||
export function appRequiresHostFrame(id: string, installedVersion?: string): boolean {
|
||||
const entry = verifiedLaunchEntry(id)
|
||||
return Boolean(entry && (installedVersion === undefined || entry.version === installedVersion)
|
||||
&& entry.manifest?.app?.metadata?.launch?.requires_host_frame === true
|
||||
&& entry.manifest.app.metadata.launch.open_in_new_tab !== true)
|
||||
}
|
||||
let launchPolicyRequest: Promise<void> | null = null
|
||||
export function appLaunchPolicyLoaded(): boolean { return signedCatalogCache !== null }
|
||||
/** Read only the authenticated daemon-verified catalog; community fallback
|
||||
* metadata must never grant a native integration. */
|
||||
export async function ensureAppLaunchPolicy(): Promise<void> {
|
||||
if (signedCatalogCache) return
|
||||
if (!launchPolicyRequest) launchPolicyRequest = (async () => {
|
||||
try {
|
||||
const response = await fetch('/api/app-catalog', {credentials:'include',signal:AbortSignal.timeout(5000)})
|
||||
if (!response.ok) return
|
||||
const value = await response.json() as SignedAppCatalog
|
||||
if (value.apps && !Array.isArray(value.apps)) signedCatalogCache = value
|
||||
} catch { /* Unavailable policy cannot authorize a new integration. */ }
|
||||
finally { launchPolicyRequest = null }
|
||||
})()
|
||||
await launchPolicyRequest
|
||||
}
|
||||
|
||||
/** Resolve node-owned launch policy independently of the public storefront.
|
||||
|
||||
Reference in New Issue
Block a user