Repository navigation
fix: accept the app.gleap.ai dashboard in the admin builder - #167
Merged
Merged
Conversation
The dashboard moved to app.gleap.ai. The product tour / tooltip builder only accepted messages from https://app.gleap.io and always loaded its iframe from app.gleap.io, so the visual editor broke for teams on app.gleap.ai. - Admin/builder messages are accepted from an exact allowlist (https://app.gleap.ai, https://app.gleap.io); no suffix or wildcard match. - The builder iframe loads from the origin of the validated `load` message, defaulting to https://app.gleap.ai. - Messages to the opener (after `load`) and to the builder iframe are posted to that origin instead of '*'. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The dashboard moved from
app.gleap.iotoapp.gleap.ai.GleapAdminManageronly accepted postMessage events fromhttps://app.gleap.ioand always loaded the builder iframe fromhttps://app.gleap.io/producttourbuilder//tooltipbuilder, so the product tour / tooltip visual editor broke for teams onapp.gleap.ai.What
src/GleapAdminOrigins.js: exact allowlist['https://app.gleap.ai', 'https://app.gleap.io'], checked with an exact string match (no suffix / wildcard / case folding), defaulthttps://app.gleap.ai.loadmessage the SDK remembersevent.originand loads the builder iframe from it (<origin>/producttourbuilderor/tooltipbuilder); without one it falls back tohttps://app.gleap.ai.load, messages to the opener go to that origin instead of'*'(the initialinitping still uses'*', since the origin isn't known yet and it carries no data); messages to the builder iframe go to the builder origin.Pairs with the redirect exclusion for
/producttourbuilder*,/tooltipbuilder*and/.well-known/*onapp.gleap.io: sessions opened from an oldapp.gleap.iotab keep loading the builder fromapp.gleap.io.Tests
src/GleapAdminOrigins.test.js: accepts both hosts; rejectshttps://app.gleap.ai.evil.com,https://evilgleap.ai, subdomains,http://, other ports, upper case, trailing slash,null/empty/non-strings; aloadfrom a lookalike origin is ignored; the builder iframe follows the opener origin (.aiand.io) and defaults toapp.gleap.ai.npm test29 suites / 505 tests pass;npm run buildpasses (build outputs not committed, as with other non-release PRs). No version bump.🤖 Generated with Claude Code