Repository navigation
Conversation
This was referenced Sep 21, 2026
Closed
irzhywau
added this pull request to stack #77
September 29, 2026 11:16
The gateway enforces Cross-Origin-Embedder-Policy: require-corp and the Home GUI desktop renders from an opaque sandboxed frame. The background image route only set Content-Type, so Chrome blocked the uploaded wallpaper with NotSameOriginAfterDefaultedToSameOriginByCoep even though the bytes were saved and served. Mirror the capsule asset route and assert the header in the existing round-trip test. Co-authored-by: Cursor <cursoragent@cursor.com>
The Home session cookie is SameSite=Strict, so a CSS url() request from the opaque Home GUI frame cannot be relied on to carry it. Fetch the image with x-elastos-home-token like every other Home request, apply it as an object URL keyed by the versioned summary URL, revoke on change, and fall back to the default wallpaper if the fetch fails. Co-authored-by: Cursor <cursoragent@cursor.com>
The dialog heading already names the file; writing 'Previewing …' into the toolbar pushed the search and view controls. Clear the status on preview and cap #status-text so no transient message can shift layout. Co-authored-by: Cursor <cursoragent@cursor.com>
Render image files with their own thumbnail instead of the generic icon. Only on-screen items are fetched (IntersectionObserver), at most three at a time, capped at 4 MB, through the download authority Library already holds; object URLs are released past 160 entries. Prefers thumbnail_uri when the Runtime provides one. Co-authored-by: Cursor <cursoragent@cursor.com>
The wallpaper GET only accepted the Home host token, yet the desktop is drawn by the active shell (home-gui) from an opaque frame with its own launch token, so every fetch returned 403 and the default wallpaper stayed. Accept the same authority the appearance-preferences POST already grants the active shell; ordinary app tokens are still refused. Co-authored-by: Cursor <cursoragent@cursor.com>
…er preview Chrome refocuses a file input when its picker closes and scrolls every scrollable ancestor to reveal it, including overflow:hidden .settings-container, which shifted the whole System window up. Hidden file inputs are now viewport-anchored so nothing needs to scroll. The background preview used a CSS url() that cannot carry the session from an opaque frame; load it through the launch token like other System requests. Co-authored-by: Cursor <cursoragent@cursor.com>
Status text in the toolbar displaced the search and view controls whenever a message appeared. Move it to the statusbar, where it takes the spare middle space and truncates first, and drop the file name from the preview loading message. Co-authored-by: Cursor <cursoragent@cursor.com>
…bjects
POST /api/apps/home/appearance/background-image { source_uri } lets the
appearance authority (Home host, System, active shells) make a stored object
the wallpaper. The Runtime reads the protected object itself under the
caller's principal root, sniffs PNG/JPEG/WebP/GIF from the bytes, applies the
same size rule as the byte upload and saves through the same path. App
tokens are refused; foreign, missing, non-image and non-localhost sources
answer 400.
Co-authored-by: Cursor <cursoragent@cursor.com>
Library expresses the intent (home:set-desktop-background) and never gains appearance authority. The Home host accepts it from Library only, with exact message keys and a localhost://Users/ URI, performs the change with its own authority and refreshes the summary so the desktop repaints. The menu item is offered for PNG/JPEG/WebP/GIF objects within the wallpaper size limit. Co-authored-by: Cursor <cursoragent@cursor.com>
SashaMIT
marked this pull request as draft
September 29, 2026 15:08
SashaMIT
removed this pull request from stack #77
September 29, 2026 15:50
SashaMIT
changed the base branch from
fix/0.7.1-security
to
feat/0.7.1-models
September 29, 2026 15:50
SashaMIT
force-pushed
the
feat/library-set-desktop-background
branch
from
September 29, 2026 15:50
b60ace8 to
c3ac261
Compare
6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rebased onto
feat/0.7.1-models(501b411c1). The 9 wallpaper/Library commits apply with no conflicts; independent of #68.What a person sees
Why the wallpaper was broken
Cross-Origin-Embedder-Policy: require-corp; the wallpaper response carried noCross-Origin-Resource-Policy, so the browser dropped it. Nowcross-origin+nosniff.url()cannot carry theSameSite=Strictsession. They now fetch with their launch token and apply an object URL (with caching, no retry storms).GET /api/apps/home/appearance/background-imageonly accepted the Home host token; the active shell that renders the desktop was refused. It now usesrequire_home_active_shell_token_context, the same authority the shell already uses to write preferences. Ordinary app tokens still get 403 (tested).Set as Desktop Background — authority model
home:set-desktop-background) and never gains appearance authority; a Library token calling the route directly gets 403 (tested).libraryonly (policy set, exact message keys,localhost://Users/URI), performs it with its own appearance authority and refreshes the summary.POST /api/apps/home/appearance/background-image { source_uri }reads the protected object itself under the caller's principal root, sniffs PNG/JPEG/WebP/GIF from the bytes, applies the same 5 MB rule and saves through the same path as the System byte upload. Foreign-principal, missing, non-image and non-localhost://sources answer 400 (tested). Bytes never traverse a capsule.Verification
cargo test -p elastos-server background_image(newtest_home_sets_background_image_from_own_object+ existing wallpaper test), fmt, clippy clean in touched files.home-entropy-check,library-menu-smoke,library-product-behavior-smoke,home-shell-bridge-smoke,home-gui-sign-out-smoke,home-shell-regression-smoke,product-ui-source.POST 200→ desktop repaints → System preview shows the same image.feat/0.7.1-models:home-entropy-checkpasses at every commit, source gate 14/14,cargo clippy --workspace --all-targets -- -D warningsclean,background_imagetests 2/2.Made with Cursor
Part of #93.