mirror of
https://github.com/saphid/frame-control.git
synced 2026-10-06 00:00:21 +02:00
A site can link to frame-control://install?manifest=URL (or ?url=URL) to install a title with Frame Control. Manifests use FrameDrop's format, so framedrop.install/v1 is accepted as well as frame-control.install/v1. - app/install-link.js parses links; main.js registers the scheme (plus electron-builder protocols for Info.plist and the .desktop file), takes links from open-url, second-instance argv and the first argv, and holds them until the page asks for them through preload's onInstallLink. - ui/frame_webinstall.py checks the URLs (HTTPS only; localhost over http only when the link itself is local; no userinfo; every address public, rechecked on redirects and pinned for the connection), reads the manifest, downloads with a size cap and sha256 check, and dispatch() sends .apk to frame_android and .zip/.exe to frame_titles when present. - server.py adds /api/webinstall/check, start, job and cancel behind the existing Host and X-Frame-UI guards; a start needs a one-time id from check. Downloads stop on cancel and on shutdown, and leftovers from a killed server are swept by PID. - index.html asks before anything downloads (name, source host, file, type, size, whether a sha256 was given) and shows progress. - docs/web-install.md, docs/install.html (landing page, unpublished). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
34 lines
1.7 KiB
JavaScript
34 lines
1.7 KiB
JavaScript
// Parses frame-control://install?manifest=URL and frame-control://install?url=URL
|
|
// (see docs/web-install.md). Pure, so it runs under plain node for the tests.
|
|
// This is only a first filter: ui/frame_webinstall.py applies the full URL rules
|
|
// (HTTPS, no private addresses, redirects) before anything is fetched.
|
|
const SCHEME = "frame-control";
|
|
const MAX_LINK = 4096;
|
|
const MAX_URL = 2048;
|
|
|
|
// {kind: "manifest" | "url", target} or null if raw isn't a usable install link.
|
|
function parseInstallLink(raw) {
|
|
if (typeof raw !== "string" || raw.length > MAX_LINK || !raw.toLowerCase().startsWith(`${SCHEME}:`)) return null;
|
|
let link;
|
|
try { link = new URL(raw); } catch { return null; }
|
|
// frame-control://install?… puts "install" in the host; accept a trailing slash too.
|
|
if (link.protocol !== `${SCHEME}:` || link.hostname !== "install" || !["", "/"].includes(link.pathname)) return null;
|
|
const keys = [...new Set(link.searchParams.keys())];
|
|
if (keys.length !== 1 || !["manifest", "url"].includes(keys[0])) return null;
|
|
const values = link.searchParams.getAll(keys[0]);
|
|
if (values.length !== 1) return null;
|
|
const target = values[0];
|
|
if (!target || target.length > MAX_URL) return null;
|
|
let parsed;
|
|
try { parsed = new URL(target); } catch { return null; }
|
|
if (!["https:", "http:"].includes(parsed.protocol) || parsed.username || parsed.password) return null;
|
|
return { kind: keys[0], target };
|
|
}
|
|
|
|
// The link among command-line arguments (Windows and Linux pass it there).
|
|
function linkFromArgv(argv) {
|
|
return (argv || []).find((a) => typeof a === "string" && a.toLowerCase().startsWith(`${SCHEME}:`)) || null;
|
|
}
|
|
|
|
module.exports = { SCHEME, parseInstallLink, linkFromArgv };
|