Skip to content

fix: accept the app.gleap.ai dashboard in the admin builder - #167

Merged
boehlerlukas merged 1 commit into
masterfrom
fix-admin-origin-gleap-ai
Oct 6, 2026
Merged

boehlerlukas merged 1 commit into
masterfrom
fix-admin-origin-gleap-ai

Conversation

@boehlerlukas

Copy link
Copy Markdown
Contributor

Why

The dashboard moved from app.gleap.io to app.gleap.ai. GleapAdminManager only accepted postMessage events from https://app.gleap.io and always loaded the builder iframe from https://app.gleap.io/producttourbuilder / /tooltipbuilder, so the product tour / tooltip visual editor broke for teams on app.gleap.ai.

What

  • New src/GleapAdminOrigins.js: exact allowlist ['https://app.gleap.ai', 'https://app.gleap.io'], checked with an exact string match (no suffix / wildcard / case folding), default https://app.gleap.ai.
  • The message listener accepts admin and builder messages only from that allowlist.
  • On the validated load message the SDK remembers event.origin and loads the builder iframe from it (<origin>/producttourbuilder or /tooltipbuilder); without one it falls back to https://app.gleap.ai.
  • Hardening: after load, messages to the opener go to that origin instead of '*' (the initial init ping still uses '*', since the origin isn't known yet and it carries no data); messages to the builder iframe go to the builder origin.
  • There was no custom/self-hosted dashboard URL option in the SDK, so nothing else changed.

Pairs with the redirect exclusion for /producttourbuilder*, /tooltipbuilder* and /.well-known/* on app.gleap.io: sessions opened from an old app.gleap.io tab keep loading the builder from app.gleap.io.

Tests

src/GleapAdminOrigins.test.js: accepts both hosts; rejects https://app.gleap.ai.evil.com, https://evilgleap.ai, subdomains, http://, other ports, upper case, trailing slash, null/empty/non-strings; a load from a lookalike origin is ignored; the builder iframe follows the opener origin (.ai and .io) and defaults to app.gleap.ai.

npm test 29 suites / 505 tests pass; npm run build passes (build outputs not committed, as with other non-release PRs). No version bump.

🤖 Generated with Claude Code

The dashboard moved to app.gleap.ai. The product tour / tooltip builder only
accepted messages from https://app.gleap.io and always loaded its iframe from
app.gleap.io, so the visual editor broke for teams on app.gleap.ai.

- Admin/builder messages are accepted from an exact allowlist
  (https://app.gleap.ai, https://app.gleap.io); no suffix or wildcard match.
- The builder iframe loads from the origin of the validated `load` message,
  defaulting to https://app.gleap.ai.
- Messages to the opener (after `load`) and to the builder iframe are posted
  to that origin instead of '*'.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
@boehlerlukas
boehlerlukas merged commit b0a4fee into master Oct 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant