mirror of
https://github.com/CopilotKit/CopilotKit.git
synced 2026-09-14 16:26:20 +08:00
28f33ecc8a
Six fixes addressing CR findings on the Option-B runtime URL-injection migration:
1. SSR_PLACEHOLDER must be parseable URL sentinels — `new URL("")` throws on
SSR causing 500s for any consumer that constructs URLs from runtime-config
fields. Use `.invalid`-TLD sentinels (RFC 2606) for URL fields; analytics
keys stay empty string. Add `suppressHydrationWarning` on consumers that
render the placeholder server-side and the real value post-hydration
(integration-grid, page-actions popover).
2. Hook-order: move `usePathname()`/`useEffect` ABOVE the early-return in
use-google-analytics. Gate the effect bodies on `GA_ID` instead so React
sees a stable hook order across renders.
3. `readUrl`/`readKey` accept either bare or `NEXT_PUBLIC_*`-prefixed env
names via a fallback chain — covers both server-only and inlined-public
variable conventions without forcing a rename across deploy targets.
4. Extract `serializeRuntimeConfig` to `lib/runtime-config-serialize.ts` so
the OWASP-escape behavior (XSS via </script>, U+2028/U+2029 line-terminator
injection) can be unit-tested without importing the layout into vitest.
5. Reclassify `intelligenceSignupUrl`/`posthogHost` from FATAL-CONFIG to
info-level in shell-docs — these are optional integrations, not hard
wiring failures, so absence should not poison the error stream.
6. Comment-rot cleanup: drop "Option B", B12, "the bug we are fixing", fix
"four substrings"→"three substrings" miscounts, and refresh shell-docs
.env.example to describe the runtime-injection contract instead of a
stale next.config throw claim.
V1: shell + shell-docs `next build` succeeds (no Edge-runtime crash on
`unstable_noStore`).
V2: `OPS_BASE_URL=` shell-dashboard `next build` no longer throws —
`next.config.ts` is now a phase-aware function that emits a sentinel
destination at build time and throws only at start (PHASE_PRODUCTION_BUILD
from next/constants).
Tests: shell-docs 72/72, shell 12/12, shell-dashboard runtime-config 16/16
(pre-existing baseline-partner-count failure unchanged).
69 lines
2.8 KiB
TypeScript
69 lines
2.8 KiB
TypeScript
import { afterEach, beforeEach, describe, expect, it } from "vitest";
|
|
import { getRuntimeConfig, type RuntimeConfig } from "./runtime-config.client";
|
|
|
|
// shell-docs's vitest runs with `environment: "node"` (no jsdom) — we
|
|
// simulate the browser by attaching a minimal `window` to globalThis
|
|
// before each test and removing it after, so we exercise BOTH the
|
|
// server-path throw (no window) and the client-path read.
|
|
|
|
type WindowWithConfig = { __SHOWCASE_CONFIG__?: RuntimeConfig };
|
|
|
|
const FULL_CONFIG: RuntimeConfig = {
|
|
baseUrl: "https://docs.example.com",
|
|
shellUrl: "https://shell.example.com",
|
|
intelligenceSignupUrl: "https://signup.example.com",
|
|
posthogKey: "phc_test",
|
|
posthogHost: "https://eu.i.posthog.com",
|
|
scarfPixelId: "scarf-id",
|
|
googleAnalyticsTrackingId: "G-TEST",
|
|
reb2bKey: "rb2b-key",
|
|
reoKey: "reo-key",
|
|
};
|
|
|
|
describe("client getRuntimeConfig (shell-docs)", () => {
|
|
beforeEach(() => {
|
|
// Attach a fresh stub `window` for each test. The cast is unavoidable
|
|
// here because globalThis.window is typed against the DOM lib and we
|
|
// are deliberately providing only the shape we need.
|
|
(globalThis as { window?: WindowWithConfig }).window = {};
|
|
});
|
|
|
|
afterEach(() => {
|
|
delete (globalThis as { window?: WindowWithConfig }).window;
|
|
});
|
|
|
|
it("returns the injected config", () => {
|
|
(globalThis as { window?: WindowWithConfig }).window!.__SHOWCASE_CONFIG__ =
|
|
FULL_CONFIG;
|
|
expect(getRuntimeConfig()).toEqual(FULL_CONFIG);
|
|
});
|
|
|
|
it("throws when __SHOWCASE_CONFIG__ is missing (wiring bug)", () => {
|
|
expect(() => getRuntimeConfig()).toThrow(
|
|
/window\.__SHOWCASE_CONFIG__ is missing/,
|
|
);
|
|
});
|
|
|
|
it("returns SSR sentinel placeholder when window is undefined", () => {
|
|
// Simulate SSR by removing window. "use client" component bodies
|
|
// execute on the server during SSR, so this reader MUST be SSR-safe
|
|
// (returns parseable-URL placeholders for URL fields so `new URL()`
|
|
// calls in consumers don't throw, and empty strings for analytics
|
|
// keys so `if (key)` truthiness gates fail-closed) — NOT throw,
|
|
// otherwise the whole server-rendered HTML 500s.
|
|
delete (globalThis as { window?: WindowWithConfig }).window;
|
|
const cfg = getRuntimeConfig();
|
|
// URL fields must be parseable so `new URL()` in consumers doesn't throw.
|
|
expect(() => new URL(cfg.baseUrl)).not.toThrow();
|
|
expect(() => new URL(cfg.shellUrl)).not.toThrow();
|
|
expect(() => new URL(cfg.intelligenceSignupUrl)).not.toThrow();
|
|
expect(() => new URL(cfg.posthogHost)).not.toThrow();
|
|
// Analytics keys stay empty so `if (key)` gates fail-closed on SSR.
|
|
expect(cfg.posthogKey).toBe("");
|
|
expect(cfg.scarfPixelId).toBe("");
|
|
expect(cfg.googleAnalyticsTrackingId).toBe("");
|
|
expect(cfg.reb2bKey).toBe("");
|
|
expect(cfg.reoKey).toBe("");
|
|
});
|
|
});
|