Skip to content

fix(desktop): only accept the dev renderer URL when one is configured - #109

Closed
woodsonl wants to merge 1 commit into
NVIDIA:developfrom
woodsonl:fix/safe-handle-origin-prefix
Closed

woodsonl wants to merge 1 commit into
NVIDIA:developfrom
woodsonl:fix/safe-handle-origin-prefix

Conversation

@woodsonl

Copy link
Copy Markdown

Description

isKnownSender treated any URL as known in a packaged build.
ELECTRON_RENDERER_URL is unset there, so process.env.ELECTRON_RENDERER_URL ?? ''
produced the empty string, and url.startsWith('') is always true. The sender
check admitted any frame, not just the dev renderer.

This requires a configured dev URL and matches it exactly (or as a path
prefix), so the check admits the dev server origin and nothing else.

Release intent

Changelog title

n/a

Changelog body

n/a

Bumps

  • services: none
  • nvpair-cluster-manager: none
  • nvpair-engine-manager: none
  • nvpair-errors: none
  • nvpair-job-scheduler: none
  • nvpair-manual-nodes: none
  • nvpair-node-info: none
  • nvpair-node-scanner: none
  • nvpair-node-settings: none
  • nvpair-proxy: none
  • nvpair-tui: none
  • nvpair-ui-broker: none
  • nvpair-workload-manager: none

Scope

Included: the isKnownSender URL check and its test. Desktop-only; no service
binary changes.

Excluded: nothing else in the IPC layer.

Validation

  • npm run typecheck in desktop/
  • npx vitest run tests/modular/safe-handle-sender.test.ts covers the unset
    dev URL, an exact match, and an unrelated URL.

Risk

Low. An unrelated URL is now correctly rejected; the dev server URL still
passes.

Checklist

  • I have read the Contributing Guidelines.
  • Every commit is signed off (git commit -s), certifying the Developer Certificate of Origin.
  • New or existing tests cover the change.
  • Relevant documentation is updated.
  • I checked the diff, changed filenames, and commit messages for credentials, private data, internal URLs, internal issue identifiers, and generated artifacts.
  • I recorded the validation commands and results above.
  • I declared version bumps in the release-intent block above. services/versions.json is written by automation — do not edit it by hand.

isKnownSender treated any URL as known in a packaged build:
ELECTRON_RENDERER_URL is unset there, so process.env.ELECTRON_RENDERER_URL
?? '' yielded the empty string and url.startsWith('') is always true. The
sender check then admitted any frame, not just the dev renderer.

Require a configured dev URL and match it exactly (or as a path prefix),
so the check admits the dev server origin and nothing else. A trailing
slash on the configured URL is stripped first, otherwise the '' + '/'
prefix doubles up and rejects the dev server's own query-string loads.
Add coverage for the unset, exact-match, trailing-slash, and unrelated-URL
cases.

Signed-off-by: woodsonl <65194841+woodsonl@users.noreply.github.com>
@woodsonl woodsonl closed this Sep 24, 2026
@woodsonl
woodsonl deleted the fix/safe-handle-origin-prefix branch September 24, 2026 05:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant