Repository navigation
fix: restore embedded dock and rpc auth in web container - #441
webfansplz wants to merge 1 commit into
Conversation
|
@webfansplz is attempting to deploy a commit to the NuxtLabs Team on Vercel. A member of the Team first needs to authorize it. |
|
👁️🗨️ Review this pull request with grouped, summarized diffs at: raw result💭 analyzed by {
"headSha": "bc98b1e8495542686c5edc1305489e48c5bb2d8d",
"result": {
"overallSummary": "Restores two regressions affecting the web-container experience: the embedded dock was incorrectly hidden whenever running inside any iframe (now it only hides inside actual Hub panels), and RPC authentication/session calls were failing because WebContainer dropped the AsyncLocalStorage session context across async setup/validation steps (now the session scope is entered immediately before the handler runs). Tests for both fixes are included.",
"groups": [
{
"key": "rpc-session-auth",
"label": "RPC session auth fix",
"summary": "Fixes WebContainer losing the RPC session's AsyncLocalStorage context during async setup/arg validation by entering the session scope right before invoking the resolved handler, so authorization and session-bound calls (like OTP verification) work correctly.",
"category": "security",
"filePaths": [
"packages/devframe/src/node/rpc-core.ts"
],
"critical": true
},
{
"key": "embedded-dock-visibility",
"label": "Embedded dock visibility fix",
"summary": "Replaces the naive `window.parent !== window` check with `isInsideHub`, which only skips mounting the embedded dock when the parent frame actually exposes a Hub client context, fixing dock hiding in cross-origin previews like StackBlitz.",
"category": "ui",
"filePaths": [
"packages/hub-ui/src/client/embedded/index.ts",
"packages/hub-ui/src/client/embedded/is-inside-hub.ts"
],
"fileNotes": [
{
"path": "packages/hub-ui/src/client/embedded/is-inside-hub.ts",
"text": "Cross-origin parent access throws a SecurityError, which is caught and treated as 'not inside Hub' so previews on different origins still mount the dock."
}
]
},
{
"key": "tests",
"label": "Tests for both fixes",
"summary": "Adds regression tests covering session isolation/auth behavior of the RPC resolver and the new `isInsideHub` detection logic.",
"category": "tests",
"filePaths": [
"packages/devframe/src/node/__tests__/rpc-core.test.ts",
"packages/hub-ui/src/client/embedded/is-inside-hub.test.ts"
]
}
],
"schemaVersion": 1,
"source": "llm",
"generatedAt": "2026-10-07T06:10:07.047Z",
"model": "vercel-ai-gateway/anthropic/claude-sonnet-5",
"locale": "en"
}
} |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The changes address both reported regressions with focused implementation and comprehensive regression tests.
Review effort: Balanced
Findings: None
What changed in this PR
Restores the embedded dock and RPC authentication behavior in WebContainer environments.
Changes:
- Detects actual Hub parent contexts instead of suppressing all iframe docks.
- Restores RPC session scope immediately before handler execution.
- Adds regression coverage for iframe detection, validation, authorization, setup retries, and concurrent sessions.
| File | Description |
|---|---|
packages/hub-ui/src/client/embedded/is-inside-hub.ts |
Detects Hub panel parents safely. |
packages/hub-ui/src/client/embedded/is-inside-hub.test.ts |
Tests top-level, same-origin, cross-origin, and Hub contexts. |
packages/hub-ui/src/client/embedded/index.ts |
Uses Hub-aware dock suppression. |
packages/devframe/src/node/rpc-core.ts |
Restores session scope around RPC handlers. |
packages/devframe/src/node/__tests__/rpc-core.test.ts |
Covers RPC session isolation and failure paths. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Be related to vitejs/devtools#603: