Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 82f7fa7545 |
31
main.js
31
main.js
@@ -659,37 +659,30 @@ ipcMain.on('create-view', async (_event, name, url, imageUrl, _zoom, useProxy) =
|
|||||||
trackNavigation(newUrl);
|
trackNavigation(newUrl);
|
||||||
});
|
});
|
||||||
view.webContents.on('will-redirect', (_e, u) => trackNavigation(u));
|
view.webContents.on('will-redirect', (_e, u) => trackNavigation(u));
|
||||||
view.webContents.setWindowOpenHandler(({ url: newUrl, frameName, features }) => {
|
view.webContents.setWindowOpenHandler(({ url: newUrl }) => {
|
||||||
let newHostname = '';
|
let newHostname = '';
|
||||||
try { newHostname = new URL(newUrl).hostname; } catch (_) {}
|
try { newHostname = new URL(newUrl).hostname; } catch (_) {}
|
||||||
|
|
||||||
// Trusted domain → open as real popup BrowserWindow with same session.
|
// Trusted domain (Google, Yandex, etc.) → navigate IN-PLACE, no popup.
|
||||||
// This is what OAuth flows need: window.opener.postMessage() works,
|
// 1.0.1 tried opening a real popup BrowserWindow here for OAuth postMessage
|
||||||
// popup can close itself when done, parent stays on the original page.
|
// flows — turns out Google specifically detects popup-style embedded
|
||||||
|
// browsers and blocks OAuth ("Возможно, этот браузер небезопасны").
|
||||||
|
// YouTube-style login uses standard redirect flow, so in-place navigation
|
||||||
|
// works AND avoids the popup fingerprint. 1.0.0 behavior, restored.
|
||||||
if (newHostname && isTrustedDomain(newHostname)) {
|
if (newHostname && isTrustedDomain(newHostname)) {
|
||||||
return {
|
trackNavigation(newUrl);
|
||||||
action: 'allow',
|
view.webContents.loadURL(newUrl);
|
||||||
overrideBrowserWindowOptions: {
|
return { action: 'deny' };
|
||||||
width: 520, height: 640,
|
|
||||||
parent: mainWindow,
|
|
||||||
autoHideMenuBar: true,
|
|
||||||
webPreferences: {
|
|
||||||
session: view.webContents.session,
|
|
||||||
contextIsolation: true,
|
|
||||||
nodeIntegration: false,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
};
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Untrusted cross-domain → ask the user (original behavior).
|
// Untrusted cross-domain → ask the user.
|
||||||
if (origHostname && newHostname && newHostname !== origHostname) {
|
if (origHostname && newHostname && newHostname !== origHostname) {
|
||||||
pendingNavigate = { view, url: newUrl };
|
pendingNavigate = { view, url: newUrl };
|
||||||
setConfirm(`Перейти на "${newHostname}"?`, 'navigate-confirmed');
|
setConfirm(`Перейти на "${newHostname}"?`, 'navigate-confirmed');
|
||||||
return { action: 'deny' };
|
return { action: 'deny' };
|
||||||
}
|
}
|
||||||
|
|
||||||
// Same-origin popup → just navigate the current view.
|
// Same-origin popup → navigate the current view.
|
||||||
trackNavigation(newUrl);
|
trackNavigation(newUrl);
|
||||||
view.webContents.loadURL(newUrl);
|
view.webContents.loadURL(newUrl);
|
||||||
return { action: 'deny' };
|
return { action: 'deny' };
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "ESH-Media",
|
"name": "ESH-Media",
|
||||||
"version": "1.0.8",
|
"version": "1.0.9",
|
||||||
"private": true,
|
"private": true,
|
||||||
"main": "main.js",
|
"main": "main.js",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
|
|||||||
Reference in New Issue
Block a user