aboutsummaryrefslogtreecommitdiffstats
path: root/packages
diff options
context:
space:
mode:
Diffstat (limited to 'packages')
-rw-r--r--packages/meshbay-client/src/main.js10
-rw-r--r--packages/meshbay-hub/tests/test_desktop_shell.py11
2 files changed, 18 insertions, 3 deletions
diff --git a/packages/meshbay-client/src/main.js b/packages/meshbay-client/src/main.js
index 794477b..c263d2c 100644
--- a/packages/meshbay-client/src/main.js
+++ b/packages/meshbay-client/src/main.js
@@ -499,9 +499,13 @@ function publicKeyB64(privateKey) {
return der.subarray(der.length - 32).toString('base64');
}
-// Everything the interface is allowed to ask Chromium for. Watching a film
-// full-screen is the whole list.
-const GRANTED_PERMISSIONS = new Set(['fullscreen']);
+// Everything the interface is allowed to ask Chromium for: watching a film
+// full-screen, and putting text on the clipboard. The second is what every Copy
+// button needs (an invitation link, the recovery key, the node key, a cast
+// URL); refused, `navigator.clipboard.writeText` rejects and each button
+// quietly did nothing. Write only, and sanitized — reading the clipboard stays
+// refused, because that is someone else's text.
+const GRANTED_PERMISSIONS = new Set(['fullscreen', 'clipboard-sanitized-write']);
// No hub call is still going to be answered after this. The hub's longest is
// signaling a WebRTC offer, which gives up at fifteen seconds of its own.
diff --git a/packages/meshbay-hub/tests/test_desktop_shell.py b/packages/meshbay-hub/tests/test_desktop_shell.py
index fcf6c4d..e6eefc2 100644
--- a/packages/meshbay-hub/tests/test_desktop_shell.py
+++ b/packages/meshbay-hub/tests/test_desktop_shell.py
@@ -96,6 +96,17 @@ def test_video_may_go_fullscreen():
assert "fullscreen" in _granted_permissions()
+def test_copy_buttons_may_write_the_clipboard_and_nothing_may_read_it():
+ """
+ Every Copy button calls `navigator.clipboard.writeText`, which Chromium
+ gates on `clipboard-sanitized-write`. With only `fullscreen` granted it was
+ refused, and each button did nothing — reported on the invitation link's.
+ """
+ granted = _granted_permissions()
+ assert "clipboard-sanitized-write" in granted
+ assert "clipboard-read" not in granted
+
+
def test_both_permission_handlers_answer_from_the_same_list():
"""`Permissions.query` takes the check handler and a request takes the
other; two lists would eventually disagree about what the page may do."""