收紧移动壳分享链接边界

移动壳分享链接归一到公开主站同源地址

补充协议相对链接和缓存回退拒绝测试

配置检查锁定分享链接归一策略

更新原生壳方案和共享决策记录
This commit is contained in:
2026-06-19 00:53:05 +08:00
parent bb85986d1f
commit af1e95febb
7 changed files with 168 additions and 16 deletions
@@ -12,6 +12,8 @@ const bridgePath = new URL('../src/host-bridge/bridge.ts', import.meta.url);
const bridgeSource = fs.readFileSync(bridgePath, 'utf8');
const dispatchPath = new URL('../src/host-bridge/dispatch.ts', import.meta.url);
const dispatchSource = fs.readFileSync(dispatchPath, 'utf8');
const sharePath = new URL('../src/host-bridge/share.ts', import.meta.url);
const shareSource = fs.readFileSync(sharePath, 'utf8');
const bridgeDirPath = new URL('../src/host-bridge/', import.meta.url);
const bridgeSourceFiles = fs
.readdirSync(bridgeDirPath, { withFileTypes: true })
@@ -945,6 +947,21 @@ for (const snippet of [
}
}
for (const snippet of [
'ALLOWED_PRODUCTION_WEB_ORIGIN',
'normalizePublicShareUrl',
"rawUrl.startsWith('//')",
'url.origin !== ALLOWED_PRODUCTION_WEB_ORIGIN',
]) {
if (!shareSource.includes(snippet)) {
throw new Error(`mobile shell share URL policy missing ${snippet}`);
}
}
if (shareSource.includes("const WEB_APP_ORIGIN = 'https://app.genarrative.world'")) {
throw new Error('mobile shell share URL policy must reuse the shared web origin');
}
for (const snippet of [
'buildMobileShellUrl(',
'HOST_BRIDGE_VERSION.toString()',