feat(server,web): serve Workspace HTML previews from a separate origin (#46)
Serve "open in new tab" HTML previews from a separate origin (the loopback counterpart, or PENGUIN_PREVIEW_ORIGIN) with a signed, host-bound token, so localStorage/cookies/third-party embeds work while Agent-generated pages stay off the app origin. The app is canonicalized onto localhost and the preview host (127.0.0.1) serves only /preview/* — its /api answers 401 and app routes 302 to the canonical host — so the preview origin can neither set nor honor a session cookie.
This commit is contained in:
@@ -63,6 +63,15 @@ export interface AuthResponse {
|
||||
|
||||
export interface MeResponse {
|
||||
user: UserInfo;
|
||||
/**
|
||||
* Whether Workspace HTML previews open on a separate origin (see design §
|
||||
* "Workspace 文件预览"). False means this deployment has no usable preview origin —
|
||||
* the App is reached on something other than a loopback name and
|
||||
* PENGUIN_PREVIEW_ORIGIN is unset — so previews fall back to the same-origin sandbox,
|
||||
* where `localStorage`, cookies and third-party embeds do not work. Computed per
|
||||
* request, since it depends on the host the caller is using.
|
||||
*/
|
||||
previewIsolated: boolean;
|
||||
}
|
||||
|
||||
export interface PasswordChangeRequest {
|
||||
|
||||
Reference in New Issue
Block a user