Summary
The Console SPA crashes with crypto.randomUUID is not a function when served over plain HTTP from any host other than localhost — e.g. accessing a dev server from another machine on the LAN via http://192.168.x.x:4001/_console/.
Root cause
crypto.randomUUID is only exposed in secure contexts (HTTPS, or http://localhost). On http://<LAN-IP>:<port> the browser simply does not provide the function, and the Console's list views crash into the ErrorBoundary ("出错了 / Something went wrong").
Repro
objectstack dev (or pnpm dev on a framework app) on machine A, port 4001.
- Add machine A's LAN origin to
OS_TRUSTED_ORIGINS so login passes CSRF.
- From machine B (or machine A itself), open
http://<machine-A-LAN-IP>:4001/_console/, log in, open any object list view.
- List area renders the error boundary; browser console shows:
TypeError: crypto.randomUUID is not a function
at .../_console/assets/vendor-react-....js
componentStack: .../_console/assets/plugin-grid-....js
Observed with @objectstack/console@17.0.0-rc.6 (vendored dist). window.isSecureContext === false on that origin confirms the context.
Suggested fix
Guard/polyfill once, early (e.g. in index.html next to the existing window.process shim, or a shared util), falling back to crypto.getRandomValues:
<script>
if (window.crypto && !window.crypto.randomUUID) {
window.crypto.randomUUID = function () {
var b = window.crypto.getRandomValues(new Uint8Array(16));
b[6] = (b[6] & 0x0f) | 0x40;
b[8] = (b[8] & 0x3f) | 0x80;
var h = Array.prototype.map.call(b, function (x) {
return x.toString(16).padStart(2, '0');
}).join('');
return h.slice(0, 8) + '-' + h.slice(8, 12) + '-' + h.slice(12, 16) + '-' + h.slice(16, 20) + '-' + h.slice(20);
};
}
</script>
We verified this exact shim (applied via pnpm patch on the vendored @objectstack/console dist) fixes the crash — list views render normally from a LAN-IP origin afterwards.
LAN-IP access to a dev box is a very common flow for demos / testing from a second device, so a built-in fallback would save every downstream app from patching this individually.
Summary
The Console SPA crashes with
crypto.randomUUID is not a functionwhen served over plain HTTP from any host other thanlocalhost— e.g. accessing a dev server from another machine on the LAN viahttp://192.168.x.x:4001/_console/.Root cause
crypto.randomUUIDis only exposed in secure contexts (HTTPS, orhttp://localhost). Onhttp://<LAN-IP>:<port>the browser simply does not provide the function, and the Console's list views crash into the ErrorBoundary ("出错了 / Something went wrong").Repro
objectstack dev(orpnpm devon a framework app) on machine A, port 4001.OS_TRUSTED_ORIGINSso login passes CSRF.http://<machine-A-LAN-IP>:4001/_console/, log in, open any object list view.Observed with
@objectstack/console@17.0.0-rc.6(vendored dist).window.isSecureContext === falseon that origin confirms the context.Suggested fix
Guard/polyfill once, early (e.g. in
index.htmlnext to the existingwindow.processshim, or a shared util), falling back tocrypto.getRandomValues:We verified this exact shim (applied via
pnpm patchon the vendored@objectstack/consoledist) fixes the crash — list views render normally from a LAN-IP origin afterwards.LAN-IP access to a dev box is a very common flow for demos / testing from a second device, so a built-in fallback would save every downstream app from patching this individually.