[DEMO] Sottodominio: DEMO_BASE -> nis2.dimostrazione.agile.software + origin allowlist postMessage
AgileHub ha consegnato il reverse-proxy nis2.dimostrazione.agile.software -> nis2.agile.software. - DemoController.DEMO_BASE default = sottodominio (spa_iframe_url/manifest/credentials lì); env DEMO_BASE_URL override. - demo-mode.js: origin-check ora ALLOWLIST (dimostrazione + nis2.dimostrazione) robusto alla topologia widget; outbound postMessage mirato all'origin reale del parent (ancestorOrigins/captured).
This commit is contained in:
+13
-4
@@ -23,7 +23,15 @@
|
||||
(function (w, d) {
|
||||
'use strict';
|
||||
|
||||
var IFRAME_ORIGIN = 'https://dimostrazione.agile.software';
|
||||
// Origin del widget/parent AgileHub. Allowlist robusta a entrambe le topologie:
|
||||
// widget sull'hub (dimostrazione.agile.software) o sul sottodominio prodotto. Da
|
||||
// confermare al collaudo E2E; intanto accettiamo entrambi (e l'origin reale viene
|
||||
// bloccato comunque all'allowlist).
|
||||
var ALLOWED_ORIGINS = ['https://dimostrazione.agile.software', 'https://nis2.dimostrazione.agile.software'];
|
||||
function parentOrigin() {
|
||||
try { var ao = w.location.ancestorOrigins; if (ao && ao.length && ALLOWED_ORIGINS.indexOf(ao[0]) >= 0) return ao[0]; } catch (e) {}
|
||||
return state.parentOrigin || ALLOWED_ORIGINS[0];
|
||||
}
|
||||
var PROTOCOL = 'agilehub.product-demo.v1';
|
||||
// Canale = RUNTIME AVATAR (postMessage widget→SPA), NON external/v1. Chiarimento AgileHub
|
||||
// 2026-06-13: il runtime avatar NON usa HMAC per-messaggio (server-to-server = X-Internal-Key,
|
||||
@@ -37,7 +45,7 @@
|
||||
var sessionId = qs.get('demo');
|
||||
if (!sessionId) return; // non in demo-mode → no-op
|
||||
|
||||
var state = { jwt: null, seed: null, channelKeyRaw: null, seen: {}, ready: false };
|
||||
var state = { jwt: null, seed: null, channelKeyRaw: null, seen: {}, ready: false, parentOrigin: null };
|
||||
|
||||
// ── util crypto ──────────────────────────────────────────────────────────
|
||||
function enc(s) { return new TextEncoder().encode(s); }
|
||||
@@ -64,7 +72,7 @@
|
||||
|
||||
// ── outbound ─────────────────────────────────────────────────────────────
|
||||
function send(type, payload) {
|
||||
try { w.parent.postMessage({ protocol: PROTOCOL, type: type, payload: payload || {}, message_id: 'spa-' + Date.now() + '-' + Math.floor(performance.now()), ts: new Date().toISOString() }, IFRAME_ORIGIN); } catch (e) { /* noop */ }
|
||||
try { w.parent.postMessage({ protocol: PROTOCOL, type: type, payload: payload || {}, message_id: 'spa-' + Date.now() + '-' + Math.floor(performance.now()), ts: new Date().toISOString() }, parentOrigin()); } catch (e) { /* noop */ }
|
||||
}
|
||||
function currentView() {
|
||||
var p = w.location.pathname.replace(/^\//, '').replace(/\.html$/, '');
|
||||
@@ -128,7 +136,8 @@
|
||||
}
|
||||
|
||||
function onMessage(ev) {
|
||||
if (ev.origin !== IFRAME_ORIGIN) return;
|
||||
if (ALLOWED_ORIGINS.indexOf(ev.origin) < 0) return;
|
||||
state.parentOrigin = ev.origin; // origin reale del widget (per outbound mirati)
|
||||
var msg = ev.data;
|
||||
if (!msg || msg.protocol !== PROTOCOL || !msg.type) return;
|
||||
verifyHmac(msg).then(function (ok) {
|
||||
|
||||
Reference in New Issue
Block a user