-
Notifications
You must be signed in to change notification settings - Fork 1
WARNING! DON'T MERGE #19
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
…nk-to-elpx-is-not-working
…able-version-refactor Integrates user theme management changes (CSS/JS handling for ELPX-imported themes) with static mode refactoring (subdirectory deployment support). Key changes merged: - User theme CSS/JS inline loading for preview - Static mode path handling for blob URL contexts - ResourceFetcher user theme methods (setUserThemeFiles, getUserTheme, getUserThemeAsync) - Static mode bundle URL generation Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
… into release/3.1-embedable-version-refactor
… into release/3.1-embedable-version-refactor
Resolved conflicts: - public/app/app.js: Combined DataProvider/adapters init with registerPreviewServiceWorker - test/e2e/playwright/specs/preview-page-updates.spec.ts: Combined imports - Deleted WebsitePreviewExporter.ts/.spec.ts (replaced by Service Worker approach)
…e/3.1-static-version
…e/3.1-static-version
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c522d20c44
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const safePath = path.normalize(pathname).replace(/^(\.\.[/\\])+/, ''); | ||
| const filePath = path.join(staticDir, safePath); | ||
|
|
||
| // Ensure file is within static directory | ||
| if (!filePath.startsWith(staticDir)) { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Strip leading slash before joining static path
The static server normalizes pathname but keeps the leading /, so path.join(staticDir, safePath) discards staticDir and yields an абсолют path like /index.html. That makes filePath.startsWith(staticDir) fail for every normal browser request (/, /index.html, /assets/...), returning 403 and preventing the Electron window from loading any static content. This breaks all static-mode launches that hit http://127.0.0.1:${STATIC_PORT}/.
Useful? React with 👍 / 👎.
No description provided.