mirror of https://github.com/garrytan/gstack.git
`validateNavigationUrl` rejected every non-http(s)/file scheme, including
`about:blank`. But the daemon opens its own first tab on about:blank, so once it
restarted it could never come back:
$ browse newtab about:blank
Blocked: scheme "about:" is not allowed. Only http:, https:, and file: URLs
are permitted.
The visible damage is in make-pdf, whose Chromium smoke test is exactly that
command. `make-pdf setup` reports:
[2/5] Launching Chromium... FAIL
Chromium failed to launch: browse newtab exited 1
against a completely healthy Chromium, and generate fails downstream with
`page.pdf: Protocol error (IO.read): Read failed` — talking to a daemon that
never finished starting. Both symptoms point away from the actual cause, which
is why this took a while to find.
It only reproduces once the daemon restarts. A daemon still holding its original
tab keeps working, so the bug hides until something recycles the process, and
then make-pdf is dead until the machine is rebooted or the tab is recreated by
some other means.
Scoped as narrowly as it can be: about:blank EXACTLY, matched on href, not the
`about:` scheme. about:blank has no origin, loads nothing and runs nothing;
about:config and about:net-internals are real surfaces and stay blocked, as does
about:blankfoo — this is not a prefix test.
Compared lower-cased because the URL parser normalises the protocol but not the
opaque part, so `ABOUT:BLANK` parses to href `about:BLANK`. Caught by the test
rather than by reading the spec.
Tests: 4 added — about:blank resolves, case-insensitively; about:config and
about:net-internals still rejected; about:blankfoo still rejected.
Note for reviewers on Windows: browse/test/url-validation.test.ts has 5
pre-existing failures on this platform, all in the file:// suites, which assume
POSIX paths (/tmp, /etc/passwd). Unrelated to this change and unchanged by it —
same 5 before and after.
|
||
|---|---|---|
| .. | ||
| bin | ||
| scripts | ||
| src | ||
| test | ||
| PLAN-snapshot-dropdown-interactive.md | ||
| SKILL.md | ||
| SKILL.md.tmpl | ||