chore: update ref to docs (🤖) - #1227
electron-pr-approver[bot] merged 1 commit into
Conversation
Deploying electron-website with
|
| Latest commit: |
57baba2
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://a7530038.electron-website.pages.dev |
| Branch Preview URL: | https://docs-update-to-b2004823e907e.electron-website.pages.dev |
| session.defaultSession.setPermissionRequestHandler((webContents, permission, callback) => { | ||
| const parsedUrl = new URL(webContents.getURL()) | ||
|
|
||
| // Verify URL | ||
| if (parsedUrl.protocol !== 'https:' || parsedUrl.host !== 'example.com') { | ||
| // Denies the permissions request | ||
| return callback(false) | ||
| } | ||
| }) | ||
| if (permission === 'notifications') { | ||
| // Approves the permissions request | ||
| callback(true) | ||
| } | ||
|
|
||
| // Verify URL | ||
| if (parsedUrl.protocol !== 'https:' || parsedUrl.host !== 'example.com') { | ||
| // Denies the permissions request | ||
| return callback(false) | ||
| } |
There was a problem hiding this comment.
🟣 pre-existing, not blocking: Pre-existing: this reformatted example handler never calls callback for any non-'notifications' permission from an allowed https://example.com origin, so real apps copying it leave the permission Promise unresolved forever. callback(true) at line 315 also lacks a return, so a 'notifications' request from a disallowed origin gets both callback(true) and callback(false) called. Fix: return callback(true) for approved cases and always call callback(false) as the fallback for every other permission/origin combination, not just when the URL check fails.
A small fix can ride a push you are already making; otherwise a short reply is enough.
Why this was flagged
Trigger: a page requests any permission other than 'notifications' (e.g. 'clipboard-read') while its origin is https://example.com. The handler at security.md:310-322 runs the notifications branch (skipped, no callback), then the URL check at 318-319 is false (origin matches), so no callback() call executes on either path. Base behavior is identical since this hunk only reformats whitespace/chaining style, not logic, so this is a pre-existing doc bug this diff touches. Result for a developer copying this snippet: the requesting renderer's permission Promise never resolves, hanging the page's feature-detection code indefinitely. No safeguard catches this because setPermissionRequestHandler has no default timeout.
Verification: pre-existing: The doc example at docs/latest/tutorial/security.md:310-323 is genuinely buggy as the candidate states. (a) For any permission other than 'notifications' from an https://example.com origin, line 313's branch is skipped and line 319's check is false (protocol==='https:' && host==='example.com'), so no callback() ever runs and the permission Promise never resolves. (b) callback(true)…
Automated PR to update the docs to the latest commit (b2004823e907e9a8dd4aa2e7c078963000c04e2e)