mirror of
https://github.com/stablyai/orca.git
synced 2026-10-03 00:02:19 +00:00
* fix(browser-preview): require explicit preview capabilities (STA-5758) Scope document reads to approved directories, confirm external links before opening them, revoke grants with tab lifecycle, and keep document-preview session state rollback-safe across mixed client/runtime versions. * Harden document preview lifecycle and permissions * Document preview DNS prefetch residual * Make preview E2E guest focus explicit * fix(browser-preview): entry-file-only authority for root-level docs, contained chip layout, re-issued gate paths (STA-5758) A grant whose document directory is its own request base — a doc at the workspace root, or outside any workspace — now reads nothing but the entry file until the reader approves a directory, at both the lexical and the canonical containment pass. The DNS-prefetch residual can only beacon what the page can read, and a root-level document could previously read the whole worktree silently. The identity chip's host badge overflowed the chip's layout box under squeeze (Linux CI): every row member can now shrink and truncate, verified by a width sweep in isolated Chromium down to ~120px chips. The Allow banner says what it grants: 'Allow folder', reading files in the named directory, for the life of the preview. The reliability-gate manifest command, testFiles entry, assertion refs and dated evidence naming the deleted doc-preview-external-link-bridge.test.ts are re-issued at doc-preview-external-link-confirmation.test.ts with a fresh 189/189 run; the focus-gate assertion text follows the shipped gate. * fix(browser-preview): hide the chip identity row below 24rem instead of clipping it, ellipsize the host badge, catalog the new i18n keys (STA-5758) CI's preview pane leaves the chip ~40px: no truncation shows anything there, so the Workspace-file label and host badge now hide whole below a 24rem container threshold sized so that visible implies contained. The badge text gains an inner text box — text directly inside the flex pill clipped both ends with no ellipsis. The e2e geometry oracle asserts containment when the row shows and the threshold when it does not. verify:localization-catalog: the hardening's new preview keys (and the renamed allowDirectory) join en.json via sync:localization-catalog. * feat(browser-preview): batch blocked folders into one access decision (STA-5758) Sequential per-folder banners trained the allow reflex without adding judgment — a reader cannot weigh assets/ against data/. The banner now accumulates every folder a load surfaces, names them (three, then a count, full list in the title), and grants exactly that set with one Allow-N-folders click and one reload. Dismiss fences the whole named set. The map lives behind a ref with a version tick so a dismissal fences an offer landing in the same event batch.
34 lines
1.3 KiB
TypeScript
34 lines
1.3 KiB
TypeScript
import type { DocPreviewFailure } from '../../shared/doc-preview-scheme'
|
|
|
|
export type DocPreviewGrantOwner =
|
|
| { kind: 'ssh'; connectionId: string }
|
|
| {
|
|
kind: 'runtime'
|
|
environmentId: string
|
|
worktreeSelector: string
|
|
worktreeRoot: string
|
|
}
|
|
|
|
export type DocPreviewGrantRequest = {
|
|
owner: DocPreviewGrantOwner
|
|
/** Directory that relative preview URLs resolve against. */
|
|
requestBase: string
|
|
/** Initial filesystem authority; always the opened document's directory. */
|
|
root: string
|
|
entryRelativePath: string
|
|
/** Browser page the document is being opened in; main registers its guest under this id. */
|
|
browserPageId: string
|
|
}
|
|
|
|
export type DocPreviewApi = {
|
|
docPreview: {
|
|
mintGrant: (request: DocPreviewGrantRequest) => Promise<{ grantId: string; url: string }>
|
|
revokeGrant: (grantId: string) => Promise<boolean>
|
|
authorizeDirectory: (grantId: string, relativePath: string) => Promise<boolean>
|
|
/** External link the preview guest tried to open; the renderer turns it into a browser tab. */
|
|
onExternalLink: (callback: (payload: { url: string }) => void) => () => void
|
|
/** Why the guest is showing an error body instead of the document. */
|
|
onLoadFailure: (callback: (payload: DocPreviewFailure) => void) => () => void
|
|
}
|
|
}
|