mirror of
https://github.com/saphid/frame-control.git
synced 2026-10-06 07:00:37 +02:00
Install links for websites: frame-control://install
A site can link to frame-control://install?manifest=URL (or ?url=URL) to install a title with Frame Control. Manifests use FrameDrop's format, so framedrop.install/v1 is accepted as well as frame-control.install/v1. - app/install-link.js parses links; main.js registers the scheme (plus electron-builder protocols for Info.plist and the .desktop file), takes links from open-url, second-instance argv and the first argv, and holds them until the page asks for them through preload's onInstallLink. - ui/frame_webinstall.py checks the URLs (HTTPS only; localhost over http only when the link itself is local; no userinfo; every address public, rechecked on redirects and pinned for the connection), reads the manifest, downloads with a size cap and sha256 check, and dispatch() sends .apk to frame_android and .zip/.exe to frame_titles when present. - server.py adds /api/webinstall/check, start, job and cancel behind the existing Host and X-Frame-UI guards; a start needs a one-time id from check. Downloads stop on cancel and on shutdown, and leftovers from a killed server are swept by PID. - index.html asks before anything downloads (name, source host, file, type, size, whether a sha256 was given) and shows progress. - docs/web-install.md, docs/install.html (landing page, unpublished). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
1a0e54d8bd
commit
dd9c009206
13 files changed
+1541
-10
No files matched your search
@@ -130,6 +130,27 @@ class ServerGuards(unittest.TestCase):
|
||||
status, _ = self.post("/api/launch", ["not", "an", "object"])
|
||||
self.assertEqual(status, 400)
|
||||
|
||||
def test_web_install_needs_the_app_page(self):
|
||||
# A website can only open frame-control:// links; it can't call these itself.
|
||||
link = {"url": "https://cdn.example.com/game.apk"}
|
||||
self.assertEqual(self.request("POST", "/api/webinstall/check", link)[0], 403)
|
||||
self.assertEqual(self.request("POST", "/api/webinstall/start", {"id": "x"})[0], 403)
|
||||
status, _, _ = self.request("POST", "/api/webinstall/check", link,
|
||||
{"X-Frame-UI": "1", "Host": f"evil.example:{self.port}"})
|
||||
self.assertEqual(status, 403)
|
||||
|
||||
def test_web_install_validation(self):
|
||||
for body in ({}, {"url": 5}, {"url": "http://cdn.example.com/game.apk"}, {"url": "https://10.0.0.2/game.apk"},
|
||||
{"url": "https://u:p@example.com/game.apk"}, {"url": "https://example.com/"},
|
||||
{"url": "https://1.1.1.1/game.sh"}, {"manifest": "file:///etc/passwd"},
|
||||
{"manifest": "https://example.com/m.json", "url": "https://example.com/g.apk"}):
|
||||
status, payload = self.post("/api/webinstall/check", body)
|
||||
self.assertEqual(status, 400, f"{body} -> {payload}")
|
||||
# Only an id from /check starts an install, and only once.
|
||||
self.assertEqual(self.post("/api/webinstall/start", {"id": "made-up"})[0], 400)
|
||||
self.assertEqual(self.request("GET", "/api/webinstall/job?id=x", headers={"X-Frame-UI": "1"})[0], 404)
|
||||
self.assertEqual(self.post("/api/webinstall/cancel", {"job": "x"})[0], 404)
|
||||
|
||||
def test_unknown_routes(self):
|
||||
self.assertEqual(self.request("GET", "/nope")[0], 404)
|
||||
self.assertEqual(self.post("/api/nope", {})[0], 404)
|
||||
|
||||
Reference in new issue
Block a user