Repository navigation
fix(catalog): 3D previews load their scripts under the docs host's script policy - #5090
Merged
Merged
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
| const code = outputFiles[0]?.text; | ||
| if (!code) throw new Error("catalog-script-inlining: esbuild produced no output."); | ||
| if (external.length === 0) return `"use strict";${code}`; | ||
| const shared = `(s)=>globalThis.${SHARED_MODULES_GLOBAL}[${JSON.stringify(SHARED_ALIASES)}[s]??s]`; |
| if (!code) throw new Error("catalog-script-inlining: esbuild produced no output."); | ||
| if (external.length === 0) return `"use strict";${code}`; | ||
| const shared = `(s)=>globalThis.${SHARED_MODULES_GLOBAL}[${JSON.stringify(SHARED_ALIASES)}[s]??s]`; | ||
| return `(function(require){"use strict";${code}})(${shared});`; |
Edit accuracy: accurate 2055 (base branch 2055), smooth 1582 of thoseThe gate passes. Quarantined, measured but not gated (0) Unstable (2)
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The four 3D-motion catalog previews that loaded their libraries through
blob:script URLs (Code Slice Hero, Cuboid Carousel, Orbit Card, Frost Sequence Camera Orbit) now run every script as an inline<script>. The docs site's policy allows that, so the live player renders the composition instead of its empty base.Why
The docs host sends
script-src 'self' 'unsafe-inline' 'unsafe-eval' https:and noblob:.scripts/catalog-script-inlining.tsfetched GSAP and the three.js modules from/public/catalog/vendor/*.json, wrapped them inURL.createObjectURL(new Blob(...))and loaded those as scripts and as import-map targets. Chrome refuses every one of them ("Loading the script 'blob:…' violates the following Content Security Policy directive"), the bootstrap's promise rejects with a bareEvent, GSAP never defineswindow.gsap, and the composition stays on its empty base: a white player for Code Slice Hero on both the gallery and its own detail page. Reproduced in Chrome 154 on the deployed/catalog/blocks/code-slice-hero.Related work
The same policy also refuses
fetch()of adata:URL (connect-src), which Glass Shard Title uses for its HDR environment. That is a separate item and a separate fix; it is not in this PR. A failed-state UI for a preview whose scripts fail is also a follow-up.How
shadows.js/surface.js, and each composition script) run through one bootstrap per item. It fetches each vendor JSON and appends the text as an inline<script>with a//# sourceURL=hyperframes-catalog://<item>/<name>, in order, so an error keeps a real source. This matches the separate<script>tags of the original composition more closely than the old indirecteval. A failed fetch is logged against the item instead of rejecting silently.three.coreimport and the two addons go into one sharedvendor/three-modules.json. It definesglobalThis.__hfCatalogModuleskeyed by import specifier, and the four raw three.js vendor files it replaces are removed.cuboid-motion.js,orbit-scene.js,orbit-motion.js) become one classic script per item. Their three.js imports stay external and resolve through that shared bundle via therequireesbuild emits for an external import.esbuild(already in the tree through tsx and the package builds) is declared at the root, because the generator now imports it.generate-catalog-payloads.ts --only <item>, so the fix ships when this merges, without waiting for the standing publish PR. The deployed payloads match main's committed files byte for byte, so the docs site servesdocs/from main. The next "Publish catalog" run regenerates the same files.Test plan
Unit tests added/updated, in
scripts/catalog-script-inlining.test.ts:blocks/orcomponents/payload does either.All five fail on main, the generator tests and the committed payloads respectively, and pass here: 14/14, 3 runs. The import-map test is replaced by one that checks each 3D item takes only three.js specifiers from the shared bundle and keeps no import map or module script.
Script-string encoding regression: closing tags, mixed-case tags, HTML comment markers, and Unicode line separators stay data and round-trip unchanged. The test fails before the fix; all 15 inlining tests pass in three serial runs. Chrome 154 also executes the generated script and parses the following element.
The four superseded vendor payloads are listed explicitly in the existing deletion guard. Its 8 tests pass.
Manual testing performed: Chrome 154, each payload mounted in a
srcdociframe under a page that sends the docs host's exact CSP.generate-catalog-payloads.test.ts,check-docs-catalog,tscfor scripts, format, lint, Fallow (no new findings from these files), the comment ratchet, comment citations and tracked artifacts pass.Comments follow CONTRIBUTING.md "Comments".
Before
The live site, Chrome 154 with a mouse (the gallery mounts live players only for a hover-capable pointer), under the deployed CSP. On the gallery, the hovered Code Slice Hero card plays as a blank white player; its detail page plays blank white too.
After
The same live pages and CSP, with only the
/public/catalog/blocks/*and/public/catalog/vendor/*requests answered from this branch's files: the card plays its headline, the detail page plays to its rear headline, and no CSP refusal is logged.