Skip to content

Commit 4923d31

Browse files
committed
fix(livepreview): preserve private transport setup in production
Replace the declaration-based config marker with a call that survives minification. Keep transport configuration private and retain the captured globals and runtime sealing.
1 parent 465bb35 commit 4923d31

2 files changed

Lines changed: 23 additions & 25 deletions

File tree

‎src/LiveDevelopment/BrowserScripts/LivePreviewTransportRemote.js‎

Lines changed: 6 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,8 @@
1919
*
2020
*/
2121

22+
/*global __PHOENIX_LIVE_PREVIEW_TRANSPORT_CONFIG__ */
23+
2224
// This is a transport injected into the browser via a script that handles the low
2325
// level communication between the live development protocol handlers on both sides.
2426
// The actual communication to phoenix is done via the loaded web worker below. We just post/receive all
@@ -89,13 +91,10 @@
8991

9092
(function (global) {
9193

92-
// The below line will be replaced with the transport scripts provided by the static server at
93-
// LivePreviewTransport.js:getRemoteScript() This is so that the actual live preview page doesnt get hold of
94-
// any phoenix web socket or broadcast channel ids from this closure programatically for security.
95-
96-
//Replace dynamic section start
97-
const TRANSPORT_CONFIG={};
98-
//Replace dynamic section end
94+
// getRemoteScript() replaces this call with a private config initializer before serving the script.
95+
// A call survives minification without depending on declaration spacing or merged const statements.
96+
// Its unknown return value also prevents the minifier from folding config property reads.
97+
const TRANSPORT_CONFIG = __PHOENIX_LIVE_PREVIEW_TRANSPORT_CONFIG__();
9998

10099
// The page's own scripts run after this one and may patch built-ins to read or rewrite what goes
101100
// to and from the editor. The channel uses the originals, captured here before any of them runs.

‎src/LiveDevelopment/MultiBrowserImpl/transports/LivePreviewTransport.js‎

Lines changed: 17 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -63,30 +63,29 @@ define(function (require, exports, module) {
6363
let _transportBridge;
6464

6565
/**
66-
* Returns the script that should be injected into the browser to handle the other end of the transport.
66+
* Fill the remote script's config initializer, preserving its private scope in source and minified builds.
6767
* @return {string}
6868
*/
6969
function getRemoteScript() {
70-
const replaceString = "const TRANSPORT_CONFIG={};";
70+
const replaceString = "__PHOENIX_LIVE_PREVIEW_TRANSPORT_CONFIG__()";
7171
if(!LivePreviewTransportRemote.includes(replaceString)){
72-
throw new Error("Live preview transport is expected to have replaceable template string:" +
73-
" //REPLACE_ME_WITH_LIVE_PREVIEW_TRANSPORT_CONFIG_AND_SCRIPT_DYNAMIC");
72+
throw new Error("Live preview transport is missing its config initializer: " + replaceString);
7473
}
75-
let transportScript = (_transportBridge && _transportBridge.getRemoteTransportScript &&
74+
const transportScript = (_transportBridge && _transportBridge.getRemoteTransportScript &&
7675
_transportBridge.getRemoteTransportScript()) || "";
77-
transportScript = "const TRANSPORT_CONFIG={};" +
78-
`TRANSPORT_CONFIG.PHOENIX_INSTANCE_ID = "${Phoenix.PHOENIX_INSTANCE_ID}";\n` +
79-
`TRANSPORT_CONFIG.IS_NATIVE_APP = ${Phoenix.isNativeApp};\n` +
80-
`TRANSPORT_CONFIG.PLATFORM = "${Phoenix.platform}";\n` +
81-
`TRANSPORT_CONFIG.LIVE_DEV_REMOTE_WORKER_SCRIPTS_FILE_NAME = "${LiveDevProtocol.LIVE_DEV_REMOTE_WORKER_SCRIPTS_FILE_NAME}";\n` +
82-
`TRANSPORT_CONFIG.LIVE_PREVIEW_DEBUG_ENABLED = ${logger.loggingOptions.logLivePreview};\n`+
83-
`TRANSPORT_CONFIG.TRUSTED_ORIGINS_EMBED = ${JSON.stringify(Phoenix.TRUSTED_ORIGINS)};\n`+
84-
`TRANSPORT_CONFIG.STRINGS = {
85-
UNSUPPORTED_DOM_APIS_CONFIRM: "${Strings.UNSUPPORTED_DOM_APIS_CONFIRM}"
86-
};\n`+
87-
transportScript;
88-
return LivePreviewTransportRemote.replace(replaceString, transportScript)
89-
+ "\n";
76+
const config = {
77+
PHOENIX_INSTANCE_ID: Phoenix.PHOENIX_INSTANCE_ID,
78+
IS_NATIVE_APP: Phoenix.isNativeApp,
79+
PLATFORM: Phoenix.platform,
80+
LIVE_DEV_REMOTE_WORKER_SCRIPTS_FILE_NAME: LiveDevProtocol.LIVE_DEV_REMOTE_WORKER_SCRIPTS_FILE_NAME,
81+
LIVE_PREVIEW_DEBUG_ENABLED: logger.loggingOptions.logLivePreview,
82+
TRUSTED_ORIGINS_EMBED: Phoenix.TRUSTED_ORIGINS,
83+
STRINGS: { UNSUPPORTED_DOM_APIS_CONFIRM: Strings.UNSUPPORTED_DOM_APIS_CONFIRM }
84+
};
85+
const initializer = "(function () {\nconst TRANSPORT_CONFIG = " + JSON.stringify(config) + ";\n" +
86+
transportScript + "\nreturn TRANSPORT_CONFIG;\n}())";
87+
// A callback keeps literal $ sequences in config values out of String.replace's replacement syntax.
88+
return LivePreviewTransportRemote.replace(replaceString, () => initializer) + "\n";
9089
}
9190

9291
EventDispatcher.makeEventDispatcher(exports);

0 commit comments

Comments
 (0)