收紧移动壳启动地址归一

Expo 移动壳只接受 http 和 https 基准 H5 地址

非法启动地址回退默认 H5 并继续附加宿主上下文

Deep link 继续限制为同源 H5 路径

补充启动地址检查测试和架构文档
This commit is contained in:
2026-06-18 08:19:25 +08:00
parent 94a866b48b
commit 3b3e83aa7a
8 changed files with 101 additions and 9 deletions
+38 -1
View File
@@ -1,6 +1,10 @@
import { describe, expect, test } from 'vitest';
import { buildMobileShellUrl } from './mobileShellUrl';
import {
DEFAULT_MOBILE_SHELL_WEB_URL,
buildMobileShellUrl,
resolveMobileShellBaseWebUrl,
} from './mobileShellUrl';
describe('buildMobileShellUrl', () => {
test('为 H5 附加原生移动壳上下文', () => {
@@ -47,4 +51,37 @@ describe('buildMobileShellUrl', () => {
'host.getRuntime',
);
});
test('移动壳基准 URL 只接受 http 和 https', () => {
expect(resolveMobileShellBaseWebUrl('https://app.test/path')).toBe(
'https://app.test/path',
);
expect(resolveMobileShellBaseWebUrl(' http://127.0.0.1:3000/ ')).toBe(
'http://127.0.0.1:3000/',
);
expect(resolveMobileShellBaseWebUrl('javascript:alert(1)')).toBe(
DEFAULT_MOBILE_SHELL_WEB_URL,
);
expect(resolveMobileShellBaseWebUrl('/relative/path')).toBe(
DEFAULT_MOBILE_SHELL_WEB_URL,
);
expect(resolveMobileShellBaseWebUrl('')).toBe(DEFAULT_MOBILE_SHELL_WEB_URL);
expect(resolveMobileShellBaseWebUrl(null)).toBe(
DEFAULT_MOBILE_SHELL_WEB_URL,
);
});
test('非法启动 URL 回退到默认 H5 地址并继续附加宿主上下文', () => {
const url = new URL(
buildMobileShellUrl('javascript:alert(1)', {
platform: 'android',
hostVersion: '0.1.0',
capabilities: ['host.getRuntime'],
}),
);
expect(url.toString().startsWith(DEFAULT_MOBILE_SHELL_WEB_URL)).toBe(true);
expect(url.searchParams.get('clientRuntime')).toBe('native_app');
expect(url.searchParams.get('hostShell')).toBe('expo_mobile');
});
});